FortiSoC GUI reorganization
The FortiSoC features have been organized in the following areas of the GUI:
-
Incidents & Events
-
FortiView
-
Fabric View
To create and manage events, go to Incidents & Events.
Incidents & Events includes the following:
Event Monitor |
View events generated by event handlers. For more information, see the FortiAnalyzer Administration Guide. |
Handlers |
Configure data selectors, notification profiles, basic event handlers, and correlation event handlers. For more information, see the FortiAnalyzer Administration Guide. |
Incidents |
Create and update incidents to track and analyze events. For more information, see the FortiAnalyzer Administration Guide. |
Threat Hunting |
View a log count chart and SIEM log analytics table. The Threat Hunting dashboard is only available in Fabric ADOMs when ADOMs are enabled. For more information, see the FortiAnalyzer Administration Guide. |
Log Parser |
View and manage SIEM log parsers. For more information, see the FortiAnalyzer Administration Guide. |
Outbreak Alerts |
View outbreak alerts and automatically download related event handlers and reports from FortiGuard. The FortiAnalyzer Outbreak Detection Service is a licensed feature. For more information, see the FortiAnalyzer Administration Guide. |
To review incidents and events in dashboards, go to FortiView > Monitors > Incidents & Events.
FortiView > Monitors > Incidents & Events includes the following dashboards:
Events |
This dashboard includes the following widgets:
|
Incidents |
This dashboard includes the following widgets:
|
To configure FortiSoC playbooks, go to Fabric View > Automation.
Fabric View > Automation includes the following:
Summary |
View playbook performance in a dashboard. This includes widgets for total playbooks, playbooks executed, and an actions trend. For more information, see the FortiAnalyzer Administration Guide. |
Connectors |
View the status of available connectors supported for playbook automation. For more information, see the FortiAnalyzer Administration Guide. |
Playbook |
Configure and manage playbooks. For more information, see the FortiAnalyzer Administration Guide. |
Playbook Monitor |
View playbook jobs in a table view. For more information, see the FortiAnalyzer Administration Guide. |