Skip to content
Discussion options

You must be logged in to vote

I see it, shouldn't your logsource be product: fortinet and category: firewall?

https://sigmahq.io/docs/basics/log-sources.html

Have you tried breaking up into two selections (selection1 and selection2) and setting the condition as selection1 and selection2?

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@arefalabsi
Comment options

@cm-ops
Comment options

@arefalabsi
Comment options

@cm-ops
Comment options

Answer selected by arefalabsi
@arefalabsi
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants