Refer to the exhibit.

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute.
What must be changed to allow the analyst to select Destination Host Name as an attribute?
The attribute must be selected as a Triggered Attribute so that it becomes available for incident generation and incident-title substitution. In the FortiSIEM Study Guide's rule action configuration section, FortiSIEM separates incident attributes from triggered attributes. Triggered attributes are taken from the events that cause the rule to trigger and are then available for incident display and incident context. The guide explains that the rule action step is where an analyst defines the incident generated by a rule and chooses which attributes are carried forward. If Destination Host Name is not selected in the Triggered Attributes list, FortiSIEM cannot use it as an incident attribute in the generated incident title. Option B is wrong because aggregate items are used for calculations such as COUNT, AVG, or SUM, not for making a text attribute available in the incident title. Option C is wrong because Destination Host Name is an event attribute, not an event type. Option D is unrelated; removing Destination IP would not make Destination Host Name selectable.
Currently there are no comments in this discussion, be the first to comment!