Fortinet white logo
Fortinet white logo

Administration Guide

FortiCNAPP polygraph

FortiCNAPP polygraph

Overview

The FortiCNAPP polygraph detects anomalies, generates appropriate alerts, and provides a unified view for you to help investigate and triage issues.

Use the polygraph to:

  • Monitor your infrastructure.
  • Spot IaaS account configurations that violate compliance.
  • See security gaps and changes that could put your company at risk.

The polygraph technology dynamically develops a behavioral model of your services and infrastructure. The model understands natural hierarchies including processes, containers, pods, and machines. It then develops behavioral models that the polygraph monitors in search of activities that fall outside the model’s parameters. In addition, the polygraph continually updates its models to:

  • Pinpoint exactly how a file changes.
  • Investigate anomalous alerts and activities related to FIM signals.
  • Provide cloud-wide capabilities for search, file type summaries, and detection of new files.

Filtering the polygraph by date and time range

Date and time range and parameter filters are available at the top of the page.

The Date/Time icon provides preset ranges for data that you want to display:

  • Latest hour
  • Latest day
  • Latest week
  • Latest month

You can click the dates and times adjacent to the Date/Time icon to select the start and end date and time manually.

For example, if you select Latest hour from the Date/Time range dropdown at 3 PM on May 05 2022, the polygraph includes activities that happen during the following date and time range: May 05, 2022, 2 PM to May 05, 2022, 3 PM.

The polygraph loads only activities found during the specified date and time range.

All timestamps are in local time.

FortiCNAPP polygraph

FortiCNAPP polygraph

Overview

The FortiCNAPP polygraph detects anomalies, generates appropriate alerts, and provides a unified view for you to help investigate and triage issues.

Use the polygraph to:

  • Monitor your infrastructure.
  • Spot IaaS account configurations that violate compliance.
  • See security gaps and changes that could put your company at risk.

The polygraph technology dynamically develops a behavioral model of your services and infrastructure. The model understands natural hierarchies including processes, containers, pods, and machines. It then develops behavioral models that the polygraph monitors in search of activities that fall outside the model’s parameters. In addition, the polygraph continually updates its models to:

  • Pinpoint exactly how a file changes.
  • Investigate anomalous alerts and activities related to FIM signals.
  • Provide cloud-wide capabilities for search, file type summaries, and detection of new files.

Filtering the polygraph by date and time range

Date and time range and parameter filters are available at the top of the page.

The Date/Time icon provides preset ranges for data that you want to display:

  • Latest hour
  • Latest day
  • Latest week
  • Latest month

You can click the dates and times adjacent to the Date/Time icon to select the start and end date and time manually.

For example, if you select Latest hour from the Date/Time range dropdown at 3 PM on May 05 2022, the polygraph includes activities that happen during the following date and time range: May 05, 2022, 2 PM to May 05, 2022, 3 PM.

The polygraph loads only activities found during the specified date and time range.

All timestamps are in local time.