Forcepoint Security Service Edge alert event
Set up the forcepoint-security-service-edge integration.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Detects Forcepoint SSE logs with an Alert action.
Strategy
This rule monitors all the Forcepoint SSE logs for which the Alert action is enforced by Forcepoint ONE SSE according to the set policy.
Triage and Response
- Review the specific alert action enforced by Forcepoint ONE SSE from IP Address -
{{@network.client.ip}}
to analyze the corresponding log entry to understand the context of the alert. - Determine the affected system, user, or resource related to the alert and assess the potential risk or impact based on the policy violation or enforced action. Analyze activity performed by which user and the application detail as below:
Activity- {{@activity}}
| Performed By- {{@usr.name}}
| Application- {{@application}}
- If necessary, update or refine the policy in Forcepoint ONE SSE to prevent false positives or improve enforcement.
- If the alert indicates a critical security threat or unusual activity, escalate it to the security operations team for further investigation.