I’m trying to build a custom rule in FortiSIEM with the following logic:
If a specific user (e.g., abc) deletes 3 accounts within 10 minutes, an incident should be triggered.
However, if the same user deletes another 3 accounts within the next 2 hours, the rule should not trigger again (a kind of cooldown period for that user).
If a different user (e.g., xyz) deletes 3 accounts within 10 minutes, then the rule should trigger independently for that user.
Has anyone implemented this type of per-user cooldown or suppression in FortiSIEM?
@Secusaurus @Anthony_E could you please help here
User | Count |
---|---|
2571 | |
1365 | |
796 | |
652 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.