Fortinet white logo
Fortinet white logo

User Guide

Viewing osquery Templates

Viewing osquery Templates

FortiSIEM comes with default system defined osquery templates. These templates are available on the Resources > Osquery page. These templates, and any newly created osquery templates appear on this page.

Column Description
Name The name of the osquery template.
Description

A description of what the osquery template does.

osquery The actual osquery.
Severity The configured severity for the osquery template, ranging from 1 to 10, with 10 being the highest severity.
Frequency The frequency that the osquery template is run.
Event Type The event type name associated with any events that occur under the executed osquery.
Scope An osquery template is either a System template (a default osquery template), or a User template (created by the user).

Viewing osquery Templates

Viewing osquery Templates

FortiSIEM comes with default system defined osquery templates. These templates are available on the Resources > Osquery page. These templates, and any newly created osquery templates appear on this page.

Column Description
Name The name of the osquery template.
Description

A description of what the osquery template does.

osquery The actual osquery.
Severity The configured severity for the osquery template, ranging from 1 to 10, with 10 being the highest severity.
Frequency The frequency that the osquery template is run.
Event Type The event type name associated with any events that occur under the executed osquery.
Scope An osquery template is either a System template (a default osquery template), or a User template (created by the user).