Refer to the exhibit.
Which section contains the subpattern configuration that determines how many matching events are needed to trigger the rule?
Refer to the exhibit.
Which value would you expect the FortiSIEM parser to use to populate the Application Name field?
Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?
Refer to the exhibit.
As shown in the exhibit, why are some of the fields highlighted in red?