Refer to the exhibits.

You are troubleshooting why the rule shown in the exhibit is generating incidents for successful Remote Desktop Protocol (RDP) connections with correct logins. It should only be triggering when a person fails to log in three or more times to the target device when connecting with RDP.
What is causing the rule to be triggered by correct login events? (Choose one answer)
Refer to the exhibit.

As shown in the exhibit, why are some of the fields highlighted in red?
You want to create a rule with multiple subpatterns but trigger an incident only if three different subpatterns are matched over a 24-hour period.
Where must you define the time period that the rule uses to evaluate all the subpatterns? (Choose one answer)
Refer to the exhibit.

If you group the events by Reporting Device , Reporting IP , and Application Category , how many results will FortiSIEM display?
Refer to the exhibit.

A FortiSIEM device is receiving syslog events from a FortiGate firewall. The FortiSIEM analyst is trying to search the raw event logs for the last two hours that contain the keyword " udp " . However, they are getting no results from the search, which they know should be available. Based on the filter shown in the exhibit, why are there no search results?
Refer to the exhibit.

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute.
What must be changed to allow the analyst to select Destination Host Name as an attribute?
Refer to the exhibits.


Three events are collected over 10 minutes from two servers: Server A and Server B.
Based on the settings for the rule subpattern and a 10-minute condition window, how many incidents will the servers generate?
When configuring anomaly detection machine learning, in which step must you select the fields to analyze?
How can you query the configuration management database (CMDB) in an analytics search?
Refer to the exhibit.

What is the Group: FortiSIEM Analysts value referring to?
TESTED 26 Jul 2026