Working with Incidents
When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are six views:
- Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
- List View: This tabular view enables the user to search incidents and take actions.
- Risk View: This view organizes impacted entities (Devices, Users) by Risk based on the triggered incidents.
- Incident Explorer View: This view helps users to correlate Actors (IP, Host, User) across multiple incidents, without creating multiple reports in separate tabs.
- MITRE ATT&CK ViewThis view classifies security events detected by FortiSIEM into MITRE ATT&CK categories. You can select Information Technology (IT) or Industrial Control Systems (ICS) MITRE ATT&CK view.
Note: Previously this was Attack View. - UEBA View: This view monitors the AI alerts obtained from FortiInsight.
To interact with an incident, see Acting on Incidents.
FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Filtering in the Incident Explorer View and Lookups Via External Websites.
FortiSIEM can also be configured to collect this host vulnerability data to preform CVE-Based IPS False Positive Analysis.