Debugging Rules on FortiSIEM
Hi all,
Just checking if someone is aware of a method for debugging SIEM rules when they trigger.
We have been through the testing, replay logs in a controlled environment and testing variations of the matching conditions but in production we still see the rule being triggered while the conditions match only one of the Multiple Subpattern Rules and the rule triggers (Note: The multiple subpatterns NEXT operator is bonded with AND/AND_NOT). We see the logs all arriving within the specified time window but we still get the trigger.
Is anyone aware of a debug command or a way we can debug the rule in actual production environment. We have checked phoenix.log in both glassfish and /opt/phoenix/ but it is only informational that the rule has triggered, no details on the conditions.
My fear is that this is a race condition issue.
Thanks,
Sotiris
