ExamGecko
Question list
Search
Search

Question 18 - NSE5_FSM-6.3 discussion

Report
Export

Refer to the exhibit.

Which value will FortiSIEM use to populate the Event Type field?

A.
PHL_INFO
Answers
A.
PHL_INFO
B.
phPerfJob
Answers
B.
phPerfJob
C.
PH_DSV_MON_SYS_DISK_UTIL
Answers
C.
PH_DSV_MON_SYS_DISK_UTIL
D.
diskUtil
Answers
D.
diskUtil
Suggested answer: A

Explanation:

Event Type Population: In FortiSIEM, the Event Type field is populated based on specific identifiers within the raw message or event log.

Raw Message Analysis: The exhibit shows a raw message with various components, including PH_DEV_MON_SYS_DISK_UTIL, PHL_INFO, phPerfJob, and diskUtil.

Primary Event Identifier: The PH_DEV_MON_SYS_DISK_UTIL at the beginning of the raw message is the primary identifier for the event type. It categorizes the type of event, in this case, a system disk utilization monitoring event.

Event Type Field: FortiSIEM uses this primary identifier to populate the Event Type field, providing a clear categorization of the event.

Reference: FortiSIEM 6.3 User Guide, Event Processing and Event Types section, details how event types are identified and populated in the system.

asked 18/09/2024
Rico Banagale
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first