Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sdahlke
New Contributor

Documentation Rule Making Using Custom Baseline in FortiSIEM

Hi Team, 


Looking at system rules that use certain functions like "STAT_AVG" that rely on baseline data in Fortisiem have you have to call a specific value that is contained within the event type used to create the system base line report. 

How do you create those values for custom baseline reports? Is that possible?

So for example, the following value "0.5*STAT_AVG(AVG(Event Rate):116)"  is used as an aggregate conditions in a system rule. This 116 value appears to reference a baseline report "Reporting EPS Profile" which uses the event type "PH_PROF_ET_116_EPS" as the only attribute value in the report. 

Can you only use these pre-built values to create baselines? Can you use STAT_AVG in conjunction with a user created baseline report? 

Is there any documentation explaining this process?


Please let me know if possible. 

1 REPLY 1
Anthony_E
Community Manager
Community Manager

Hello sdhalke,

 

I have found this FortiSIEM user guide:

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/6a52c49d-794a-11ec-bdf2-fa163e...

 

Does it provide the information you were looking for?

 

If not, we will continue to look for the good one.

 

Regards,

 

 

Anthony-Fortinet Community Team.
Labels
Top Kudoed Authors