Viewing osquery Templates
FortiSIEM comes with default system defined osquery templates. These templates are available on the Resources > Osquery page. These templates, and any newly created osquery templates appear on this page.
| Column | Description |
|---|---|
| Name | The name of the osquery template. |
| Description |
A description of what the osquery template does. |
| osquery | The actual osquery. |
| Severity | The configured severity for the osquery template, ranging from 1 to 10, with 10 being the highest severity. |
| Frequency | The frequency that the osquery template is run. |
| Event Type | The event type name associated with any events that occur under the executed osquery. |
| Scope | An osquery template is either a System template (a default osquery template), or a User template (created by the user). |