An analyst is encountering a large number of false positive results. Legitimate internal network traffic contains valid flows and events which are making it difficult to identify true security incidents.
What can the analyst do to reduce these false positive indicators?
How does the Custom Rule Engine (CRE) evaluates rules?
How can an analyst search for all events that include the keyword 'vims'?
Which use case type is appropriate for VPN log sources? (Choose two.)
When an analyst sees the system notification ''The appliance exceeded the EPS or FPM allocation within the last hour'', how does the analyst resolve this issue? (Choose two.)