Hello,
Ask about the Incident Status:- Active, Manaually Cleared, Automatically cleared, and System cleared.
the System cleared and the Auto cleared is performed by the system itself no interaction from the user side.
How can i use them efficiently?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Ali,
I am sorry, but I don't understand your question here.
You can only clear manually, so the auto-clear (ML or clear-condition cleared it) and system-clear (one day after incident happened) is just something to get you better understanding about the reason for clearing. So what do you have in mind for using them "efficiently"?
Best,
Christian
Ali might be saying that incidents are automatically clearing even without a rule definition defined. If so, we're seeing something similar.
What version of FortiSIEM are you running?
We were on 7.1.2. We're thinking it may have been right after we did a content update to version 608 but it seems to have resolved itself after some time though.
can you check under Admin / Settings / AI/ML if you have this enabled
Auto Clear Incidents with % False Positive Confidence
We do not have auto clear incidents with AI/ML enabled but we will definitely keep this in mind next time we see something weird with the auto clears. Thanks!
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.