Fortisiem question
Hi All, Could really use some help/ideas on this below currently we have FortiSIEM but it just produces too many false positives, can't really see the most important incidents from all the incidents it produces.
How can we reduce the amount of false positives produced? Any exclusions and rules we need to target and customize for this? we also see a lot of Permitted Traffic from Emerging Threat IP and Permitted Traffic from FortiGuard Malware IP List. surely if these are coming up as malicious surely Forti guard database should be blocking them if they are? do we have to add or find more databases to integrate them to FortiSIEM to block theses malicious IP's? Hope to hear from you all.
Thank you in advance.
