It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?

An administrator defines SMTP as a critical process on a Linux server.

It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?
A . Postfix-Mail-Stop
B . PH_DEV_MON_PROC_STOP
C . PH_DEV_MON_SMTP_STOP
D . Generic_SMTP_Procoss_Exit

Answer: B

Explanation:

Process Monitoring in FortiSIEM: FortiSIEM can monitor critical processes on managed devices, such as an SMTP process on a Linux server.

Event Generation: When a critical process stops, FortiSIEM generates an event to alert administrators.

Event Types: Specific event types correspond to different monitored conditions. For a stopped process, the event type PH_DEV_MON_PROC_STOP is used.

Reasoning: The name PH_DEV_MON_PROC_STOP (Device Monitoring Process Stop) is a generic event type used by FortiSIEM to indicate that any monitored process, including SMTP, has stopped.

Reference: FortiSIEM 6.3 User Guide, Event Types section, explains the predefined event types and their usage in different monitoring scenarios.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments