Fortinet white logo
Fortinet white logo

User Guide

Working with Incidents

Working with Incidents

When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are six views:

  • Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
  • List View: This tabular view enables the user to search incidents and take actions.
  • Risk View: This view organizes impacted entities (Devices, Users) by Risk based on the triggered incidents.
  • Incident Explorer View: This view helps users to correlate Actors (IP, Host, User) across multiple incidents, without creating multiple reports in separate tabs.
  • MITRE ATT&CK ViewThis view classifies security events detected by FortiSIEM into MITRE ATT&CK categories. You can select Information Technology (IT) or Industrial Control Systems (ICS) MITRE ATT&CK view.
    Note: Previously this was Attack View.
  • UEBA View: This view monitors the AI alerts obtained from FortiInsight.

To interact with an incident, see Acting on Incidents.

FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Filtering in the Incident Explorer View and Lookups Via External Websites.

FortiSIEM can also be configured to collect this host vulnerability data to preform CVE-Based IPS False Positive Analysis.

Working with Incidents

Working with Incidents

When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are six views:

  • Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
  • List View: This tabular view enables the user to search incidents and take actions.
  • Risk View: This view organizes impacted entities (Devices, Users) by Risk based on the triggered incidents.
  • Incident Explorer View: This view helps users to correlate Actors (IP, Host, User) across multiple incidents, without creating multiple reports in separate tabs.
  • MITRE ATT&CK ViewThis view classifies security events detected by FortiSIEM into MITRE ATT&CK categories. You can select Information Technology (IT) or Industrial Control Systems (ICS) MITRE ATT&CK view.
    Note: Previously this was Attack View.
  • UEBA View: This view monitors the AI alerts obtained from FortiInsight.

To interact with an incident, see Acting on Incidents.

FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Filtering in the Incident Explorer View and Lookups Via External Websites.

FortiSIEM can also be configured to collect this host vulnerability data to preform CVE-Based IPS False Positive Analysis.