Hi Team,
Looking at system rules that use certain functions like "STAT_AVG" that rely on baseline data in Fortisiem have you have to call a specific value that is contained within the event type used to create the system base line report.
How do you create those values for custom baseline reports? Is that possible?
So for example, the following value "0.5*STAT_AVG(AVG(Event Rate):116)" is used as an aggregate conditions in a system rule. This 116 value appears to reference a baseline report "Reporting EPS Profile" which uses the event type "PH_PROF_ET_116_EPS" as the only attribute value in the report.
Can you only use these pre-built values to create baselines? Can you use STAT_AVG in conjunction with a user created baseline report?
Is there any documentation explaining this process?
Please let me know if possible.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello sdhalke,
I have found this FortiSIEM user guide:
Does it provide the information you were looking for?
If not, we will continue to look for the good one.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.