FortiSIEM Discussions
Ali_Maher
New Contributor III

Incident Status

Hello,

 

Ask about the Incident Status:- Active, Manaually Cleared, Automatically cleared, and System cleared.

 

the System cleared and the Auto cleared is performed by the system itself no interaction from the user side.

 

How can i use them efficiently?

BR, Ali Maher
BR, Ali Maher
6 REPLIES 6
Secusaurus
Contributor II

Hello Ali,

 

I am sorry, but I don't understand your question here.

You can only clear manually, so the auto-clear (ML or clear-condition cleared it) and system-clear (one day after incident happened) is just something to get you better understanding about the reason for clearing. So what do you have in mind for using them "efficiently"?

 

Best,

Christian

FCP & FCSS Security Operations | Fortinet Advanced Partner
FCP & FCSS Security Operations | Fortinet Advanced Partner
knguyen1
New Contributor

Ali might be saying that incidents are automatically clearing even without a rule definition defined. If so, we're seeing something similar.  

FSM_FTNT
Staff
Staff

What version of FortiSIEM are you running?

knguyen1
New Contributor

We were on 7.1.2. We're thinking it may have been right after we did a content update to version 608 but it seems to have resolved itself after some time though.

FSM_FTNT
Staff
Staff

can you check under Admin / Settings / AI/ML if you have this enabled

Auto Clear Incidents with % False Positive Confidence

knguyen1
New Contributor

We do not have auto clear incidents with AI/ML enabled but we will definitely keep this in mind next time we see something weird with the auto clears. Thanks!

Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"