If a performance rule is triggered repeatedly due to high CPU use, what occurs in the incident table?
Incident Management in FortiSIEM: FortiSIEM tracks incidents and their occurrences to help administrators manage and respond to recurring issues.
Performance Rule Triggering: When a performance rule, such as one for high CPU usage, is repeatedly triggered, FortiSIEM updates the corresponding incident rather than creating a new one each time.
Incident Table Updates:
Incident Count: The Incident Count value increases each time the rule is triggered, indicating how many times the incident has occurred.
First Seen and Last Seen Times: These timestamps are updated to reflect the first occurrence and the most recent occurrence of the incident.
Reference: FortiSIEM 6.3 User Guide, Incident Management section, explains how FortiSIEM handles recurring incidents and updates the incident table accordingly.
Tamekia
5 days agoVirgie
14 days agoAlaine
18 days agoVinnie
24 days agoAdelina
13 days agoLizbeth
28 days agoShannan
1 months agoPortia
16 hours agoBasilia
1 months agoTula
14 days agoBrinda
1 months agoYen
1 months agoBrinda
2 months ago