- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`Classification:
attack
Detects security threats identified by Fortinet FortiManager UTM security products including malware infections, intrusion attempts, network anomalies, and data loss prevention violations.
This rule monitors Fortinet FortiManager UTM security events where protective actions were not automatically taken. It aggregates security alerts from multiple FortiManager security modules including antivirus, intrusion prevention system, anomaly detection, and data loss prevention. The detection focuses on events where threats were detected but not blocked, dropped, or cleared, indicating potential security incidents that require investigation.
{{@eventtype}}
and {{@subtype}}
fields to understand the nature of the security event.{{@network.destination.ip}}
or {{@network.client.ip}}
depending on the event type.