Forcepoint Security Service Edge alert event
Set up the forcepoint-security-service-edge integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Goal
Detects Forcepoint SSE logs with an Alert action.
Strategy
This rule monitors all the Forcepoint SSE logs for which the Alert action is enforced by Forcepoint ONE SSE according to the set policy.
Triage and Response
- Review the specific alert action enforced by Forcepoint ONE SSE from IP Address -
{{@network.client.ip}}
to analyze the corresponding log entry to understand the context of the alert. - Determine the affected system, user, or resource related to the alert and assess the potential risk or impact based on the policy violation or enforced action. Analyze activity performed by which user and the application detail as below:
Activity- {{@activity}}
| Performed By- {{@usr.name}}
| Application- {{@application}}
- If necessary, update or refine the policy in Forcepoint ONE SSE to prevent false positives or improve enforcement.
- If the alert indicates a critical security threat or unusual activity, escalate it to the security operations team for further investigation.