FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
FortiKoala
Staff
Staff
Article Id 195822
Description

How do AI tags work


Scope

FAQ


Solution

As AI inspects incoming events for anomalousness, it also attempts to categorise anomalous events using tags. 


Events will be inspected for particular characteristics, as defined within the AI tag definitions, and the appropriate tag, if any applied to the event.


For example, an event involving a user writing a CV file will be tagged as Potential Leaver, and events displaying common ransomware characteristics will be tagged as Ransomware.


The AI alerts page shows the most commonly detected tags via the summary table, and allows searching the list of events for particular tags.


Contributors