Rule Tags
FortiSIEM offers system level tags that are linked to appropriate system rules. These tags can be used to locate incidents and cases where a rule with an associated tag was triggered. User defined tags can also be created, and associated with rules that trigger incidents. After creating a user defined tag, you associate it with a rule (See Creating a Rule: Step 3: Define Actions). After this configuration, you can view tags on the Incidents page or Cases page by doing any of the following.
- View tag(s) on the Incidents List View or Cases List View page under the Tag column.
- Search for tag related incidents by including Incident Tag as part of your search.
- Search for tag related cases by including Tag as part of your search.
- Select an incident or case and view tag(s) in the Incident or Case sidebar.
The following topics are available.
Creating a Rule Tag
Follow these steps to create a new tag.
- Navigate to Admin > Settings > Analytics > Rule Tags.
- Click +.
- In the Rule Tags window, take the following steps:
- In the Tag field, enter a name for the tag you wish to create.
- In the Color field, select a color for the tag.
- (Optional) In the Description field, add any information you wish to convey about the tag, such as its intent.
- When done, click Save.
At this point, you tag will be saved, and be available from the Tags drop-down list when creating or editing a Rule.
Editing a Rule Tag
Follow these steps to edit a tag.
- Navigate to Admin > Settings > Analytics > Rule Tags.
- Select the rule tag you wish to edit, and click
. - In the Edit Tag: <Name of Rule Tag> window, make any changes to the Tag, Color, and Description fields.
- When done, click Save.
Deleting a Rule Tag
Follow these steps to delete a user-defined tag. System tags cannot be deleted.
|
|
Tip: On the Rule Tags page, look at the Scope column to identify whether a tag is a System tag or User (defined) tag. |
- Navigate to Admin > Settings > Analytics > Rule Tags.
- Select the rule tag you wish to delete.
- Click the Delete (
) icon.