What are the four required CPS-compliant Event parser tags?
Which Falcon LogScale Collector output format would you use if your downstream SIEM requires raw nested event data?
You notice that the format of incoming logs suddenly changes from JSON format to key-value pairs during log collection.
What action would you take to parse the data correctly?
Which three System alerts are enabled by default in Next-Gen SIEM for third-party connectors?