FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
Andy_G
Staff
Staff
Article Id 197907

Description

Summary of Topic

Best Practice to make sure you do not get more notifications than you necessarily need

 

Steps

Verify all the user made active rules are properly configured.

Make sure that multiple rules (both user and system) don't share too many similar definitions in the sub pattern, so they will not being triggered for the same type of incident. 

Proper configuration of rules and notifications will make sure you don't get spammed with email.

 

Additional Information

n/a

 

Version Application

All



 

 

Contributors