Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vinicius_azevedosw
New Contributor

Query to know unusable events on Fortisiem

Hello,

 

I need to drop some logs on FortiSIEM, and I see a lot unused events. Does anyone knows any query to see these events or a tip where to start to investigate unrelevant logs

 

Kind Regards.

Kind Regards,
Vinicius Azevedo
2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello,

 

May I propose you to have a look on KB FortiSIEM articles:

 

https://community.fortinet.com/t5/FortiSIEM/tkb-p/TKB28?pageNum=1

 

You could have some answers, tips and useful information.

 

Regards,

Anthony-Fortinet Community Team.
premchanderr
Staff
Staff

Hi ,

 

You can create event dropping rules to drop logs on Fortisiem.  

https://help.fortinet.com/fsiem/6-5-0/Online-Help/HTML5_Help/Event_Handling_Settings.htm#Event

 

The Unused events are from your EPS bucket and they can useful if there is any burst of EPS in future.  These are calculated on daily basis and added to the count.

 

Regards,
Prem Chander R