ExamGecko
Question list
Search
Search

Question 28 - NSE5_FSM-6.3 discussion

Report
Export

An administrator wants to search for events received from Linux and Windows agents.

Which attribute should the administrator use in search filters, to view events received from agents only.

A.
External Event Receive Protocol
Answers
A.
External Event Receive Protocol
B.
Event Received Proto Agents
Answers
B.
Event Received Proto Agents
C.
External Event Receive Raw Logs
Answers
C.
External Event Receive Raw Logs
D.
External Event Receive Agents
Answers
D.
External Event Receive Agents
Suggested answer: D

Explanation:

Search Filters in FortiSIEM: When searching for specific events, administrators can use various attributes to filter the results.

Attribute for Agent Events: To view events received specifically from Linux and Windows agents, the attribute External Event Receive Agents should be used.

Function: This attribute filters events that are received from agents, distinguishing them from events received through other protocols or sources.

Search Efficiency: Using this attribute helps the administrator focus on events collected by FortiSIEM agents, making the search results more relevant and targeted.

Reference: FortiSIEM 6.3 User Guide, Event Search and Filters section, which describes the available attributes and their usage for filtering search results.

asked 18/09/2024
Vijay Khara
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first