Technical Tip: Content Updates on FortiSIEM Cloud
| Description | This article describes how to perform Content Updates on FortiSIEM. |
| Scope | FortiSIEM v6.4.0 or later. |
| Solution | FortiSIEM is a distributed system, meaning that raw events can come into either the Cloud backend (with FortiSIEM Cloud deployments and the Supernode resides in the Cloud) or collector nodes(when sending local raw events to collectors). It is not mandatory to download the latest content packs to the local collectors, where content packs do not have any parsing logic applied to them, however, the best practice is to keep these as in line and updated as possible.
To perform a Content update on FortiSIEM:
|

