Refer to the exhibit. An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab. What is wrong with the rule conditions?
Several new internal servers are generating incidents and must be excluded from several FortiSIEM rules. How must you tune rules to exclude several undiscovered devices from rules?