ExamGecko
Question list
Search
Search

Question 42 - NSE5_FSM-6.3 discussion

Report
Export

Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.

Based on the selected filters shown in the exhibit, why are there no search results?

A.
The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
Answers
A.
The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
B.
In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
Answers
B.
In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
C.
The administrator selected - in the Operator column That a the wrong operator.
Answers
C.
The administrator selected - in the Operator column That a the wrong operator.
D.
The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
Answers
D.
The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
Suggested answer: A

Explanation:

Case Sensitivity in Searches: In FortiSIEM, search queries, including those for raw event logs, are case sensitive. This means that keywords must be entered exactly as they appear in the logs.

Keyword Mismatch: The exhibit shows the keyword 'TCP' in the Value field. If the actual events use 'tcp' (lowercase), the search will return no results because of the case mismatch.

Correct Keyword: To match the keyword correctly, the administrator should enter 'tcp' in the Value field.

Reference: FortiSIEM 6.3 User Guide, Search and Filtering section, which discusses the importance of case sensitivity in search queries.

asked 18/09/2024
john ignacio echavarria lopez
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first