Câu 27: XSIAM-ENGINEER: Palo Alto Networks XSIAM Engineer
A security engineer notices that in the past week ingestion has spiked significantly. Upon investigating the anomaly, it is determined that a custom application developed in-house caused the spike. The custom application is sending syslog to the Broker VM Syslog Collector applet. The engineer consults with the SOC ana…
Nội dung câu hỏi
A security engineer notices that in the past week ingestion has spiked significantly. Upon investigating the anomaly, it is determined that a custom application developed in-house caused the spike. The custom application is sending syslog to the Broker VM Syslog Collector applet. The engineer consults with the SOC analyst, who determines that 90% of the logs from the custom application are not used. What can the engineer configure to reduce the ingestion?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Parsing rule to drop the unnecessary data at the Broker VM — đáp án hiện tại
- B. Data model rule to drop the unnecessary data
- C. Correlation rule on the Cortex XSIAM server to drop the unnecessary data
- D. Data model rule to map the useful data
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.