Fortinet white logo
Fortinet white logo

User Guide

UEBA Tags

UEBA Tags

The AI module runs on Super and Worker nodes. All Agent activity is routed to one node in a sticky manner. If a Worker is down, Agent events are routed to another Worker. If a Worker is added, then new Agents are routed to that Worker. Additionally, AI models are now persisted across AI module restarts.

AI alerts can be monitored in the UEBA View in the Incidents page. See UEBA View.

AI inspects the events for specific characteristics, as defined in the AI tag definitions, and applies the appropriate tags to events that match.

Follow these steps to set tags:

  1. Click Admin > Settings > Analytics > UEBA Tags.
  2. Click + to create a new tag.
  3. Provide values for the following fields:
    1. Enabled - Select this option to allow FortiSIEM to monitor the alert.
    2. ID (required) - A user-defined ID. Only these characters are allowed: a-z, A-Z, 0-9, and the underbar character (_).
    3. Name (required) - The user-defined name for the entity. Only these characters are allowed: a-z, A-Z, 0-9, and white space.
    4. Description - An optional description of the alert.
    5. Weight - Select a value from the drop-down list. The values can range from Never Alert (-5) to Always Alert (+5).
    6. Rules
      1. Field - Choose a value from the drop-down list. Available values are Machine ID, User, Application, Activity, Resource, and Resource Filename.
      2. Relation - Choose a value from the drop-down list. Available values are =, !=, CONTAIN, NOT CONTAIN, MATCH, NOT MATCH, START WITH, NOT START WITH, END WITH, and NOT END WITH.
      3. Value - A comma-separated list of values. These values can be user-defined.
      4. Click + or - to add or delete rows in the Rules list.
  4. Click Save.

The following functions are also available for UEBA tags:

Note: System UEBA tags cannot be edited or deleted. If you wish to edit a System UEBA tag, you can clone it and then enable it.

  • Edit () - Modify a user UEBA tag.
  • Delete () - Delete a user UEBA tag.
  • Clone () - Duplicate a UEBA tag.

UEBA Tags

UEBA Tags

The AI module runs on Super and Worker nodes. All Agent activity is routed to one node in a sticky manner. If a Worker is down, Agent events are routed to another Worker. If a Worker is added, then new Agents are routed to that Worker. Additionally, AI models are now persisted across AI module restarts.

AI alerts can be monitored in the UEBA View in the Incidents page. See UEBA View.

AI inspects the events for specific characteristics, as defined in the AI tag definitions, and applies the appropriate tags to events that match.

Follow these steps to set tags:

  1. Click Admin > Settings > Analytics > UEBA Tags.
  2. Click + to create a new tag.
  3. Provide values for the following fields:
    1. Enabled - Select this option to allow FortiSIEM to monitor the alert.
    2. ID (required) - A user-defined ID. Only these characters are allowed: a-z, A-Z, 0-9, and the underbar character (_).
    3. Name (required) - The user-defined name for the entity. Only these characters are allowed: a-z, A-Z, 0-9, and white space.
    4. Description - An optional description of the alert.
    5. Weight - Select a value from the drop-down list. The values can range from Never Alert (-5) to Always Alert (+5).
    6. Rules
      1. Field - Choose a value from the drop-down list. Available values are Machine ID, User, Application, Activity, Resource, and Resource Filename.
      2. Relation - Choose a value from the drop-down list. Available values are =, !=, CONTAIN, NOT CONTAIN, MATCH, NOT MATCH, START WITH, NOT START WITH, END WITH, and NOT END WITH.
      3. Value - A comma-separated list of values. These values can be user-defined.
      4. Click + or - to add or delete rows in the Rules list.
  4. Click Save.

The following functions are also available for UEBA tags:

Note: System UEBA tags cannot be edited or deleted. If you wish to edit a System UEBA tag, you can clone it and then enable it.

  • Edit () - Modify a user UEBA tag.
  • Delete () - Delete a user UEBA tag.
  • Clone () - Duplicate a UEBA tag.