Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

kcanalichio
New Contributor III

Alerts for 0 events

Does anyone know how to create an alert in fortiseim that will alert if no events the match the filter in a 24 hours period.

I have tried matched events = 0  and matched events = NULL, but neither seem to work
1 REPLY 1
KarnGriffen
New Contributor III

There is no great way to do this.  I've attached a rule we use now that looks for a SUM(Event Rate) that is below a threshold.