FortiSIEM Discussions
Ali_Maher
New Contributor II

Incident Status

Hello,

 

Ask about the Incident Status:- Active, Manaually Cleared, Automatically cleared, and System cleared.

 

the System cleared and the Auto cleared is performed by the system itself no interaction from the user side.

 

How can i use them efficiently?

BR, Ali Maher
BR, Ali Maher
2 REPLIES 2
Secusaurus
Contributor

Hello Ali,

 

I am sorry, but I don't understand your question here.

You can only clear manually, so the auto-clear (ML or clear-condition cleared it) and system-clear (one day after incident happened) is just something to get you better understanding about the reason for clearing. So what do you have in mind for using them "efficiently"?

 

Best,

Christian

FCP & FCSS Security Operations | Fortinet Advanced Partner
FCP & FCSS Security Operations | Fortinet Advanced Partner
knguyen1
New Contributor

Ali might be saying that incidents are automatically clearing even without a rule definition defined. If so, we're seeing something similar.