Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Related to SIEM Implementation Concerns
Dear Friends,
I need your support to find answers/recommendations from FortiSIEM.
Regards,
Kalana
------------------------------
kalana
------------------------------
I need your support to find answers/recommendations from FortiSIEM.
Description | Implementation Concerns |
Log Archival Process | When restoration is required, is this happened in a bulk or can we add parameters i.e: like firewall, device, etc. |
When in restoration, is this restored into the storage of live box? | |
What will be the impact of the processing of Live SIEM afterward / Performance impact? | |
When archiving is this comply with PCI-DSS. Is this RAW log or Normalized log? | |
The customer has requested to retain application |
|
Endpoint Agent | Is this only for endpoints like desktops, laptops or can we use this for servers? |
If we can install this in an application server like IIS, is it enough to forward the logs for main |
|
What are the log types collected by, these agents? | |
Are there any limitations on a collection of logs with this agent? | |
Is an agent forwarding |
|
All in one feature concept SIEM(Ex. As SIEM like Supervisor, Worker, Collector ) | Please explain the All in one concept |
Collector device count limits | Limitation number of device per collector, or based on EPS count |
If the collector has a maximum EPS rate exceeds what is the method to continue the BAU | The queue is being cleared after 3 days, what will happen to the logs for the in-between 2 days? Is SIEM being capable enough to flag the timelines and |
Need a better explanation about this procedure(Are there any queuing methods applied) | |
Any disaster situation loss of collector connectivity and after back to normal status. | |
Lost of |
If a |
Saving location for logs | What are the Log storing locations for Raw logs and |
Regards,
Kalana
------------------------------
kalana
------------------------------
Labels:
- Labels:
-
SIEM
0 REPLIES 0
