Fortinet white logo
Fortinet white logo

Administration Guide

Managing indicators

Managing indicators

Indicators can be found in Incidents & Events > Indicators. This pane contains a chart view and table view of the indicators.

There are three charts in the chart view:

  • Indicator Type

  • Reputation

  • Enrichment Status

By default, all three charts are displayed. From the Show Charts dropdown, you can toggle which charts display. You can also toggle Show Charts to hide all charts, when needed.

Select a value in any of the charts to apply the filter to all charts and the table view. To remove the filter, click the chart title.

The following actions are available in the toolbar:

Action

Description

Create New Create a new indicator. Once the indicator is created, the Source column will display the admin that created it.

Edit

Edit the indicator.

Delete

Delete the indicator.

Enrich

Enrich the indicator. For more information, see Indicator enrichment.

The following columns are available in the table view:

Column

Description

Indicator The indicator name.

Type

The indicator type:

  • IP

  • URL

  • Domain

Rating Confidence

The rating confidence from FortiGuard.

Reputation

The reputation from VirusTotal:

  • Malicious

  • Suspicious

  • Harmless

  • Undetected

Enrichment Status

The enrichment status:

  • Enriched (completed)

  • No enrichment

  • No data

Source

The source of the enrichment:

  • <administrator name>

  • auto-created

To create a new indicator:
  1. Go to Incidents & Events > Indicators.

  2. Click Create New.

  3. From the Indicator dropdown, select the indicator type.

  4. In the Indicator Value field, enter the appropriate value for the indicator type (IP, URL, or domain).

  5. Click Create.

To edit an indicator:
  1. Go to Incidents & Events > Indicators.

  2. Select and indicator, and click Edit.

  3. Update the indicator.

  4. To save the changes, click Edit.

To delete an indicator:
  1. Go to Incidents & Events > Indicators.

  2. Select and indicator, and click Delete.

  3. To confirm the deletion, click OK.

To enrich an indicator:
  1. Go to Incidents & Events > Indicators.

  2. Select and indicator, and click Enrich.

    Alternatively, you can double-click the indicator or right-click the indicator and click Enrich.

    The Enrich pane displays.

  3. Review the details in the Enrich pane.

  4. Click Save Enrichment or Cancel according to the review.

    The indicator will only be processed and enriched after clicking Save Enrichment.

Managing indicators

Managing indicators

Indicators can be found in Incidents & Events > Indicators. This pane contains a chart view and table view of the indicators.

There are three charts in the chart view:

  • Indicator Type

  • Reputation

  • Enrichment Status

By default, all three charts are displayed. From the Show Charts dropdown, you can toggle which charts display. You can also toggle Show Charts to hide all charts, when needed.

Select a value in any of the charts to apply the filter to all charts and the table view. To remove the filter, click the chart title.

The following actions are available in the toolbar:

Action

Description

Create New Create a new indicator. Once the indicator is created, the Source column will display the admin that created it.

Edit

Edit the indicator.

Delete

Delete the indicator.

Enrich

Enrich the indicator. For more information, see Indicator enrichment.

The following columns are available in the table view:

Column

Description

Indicator The indicator name.

Type

The indicator type:

  • IP

  • URL

  • Domain

Rating Confidence

The rating confidence from FortiGuard.

Reputation

The reputation from VirusTotal:

  • Malicious

  • Suspicious

  • Harmless

  • Undetected

Enrichment Status

The enrichment status:

  • Enriched (completed)

  • No enrichment

  • No data

Source

The source of the enrichment:

  • <administrator name>

  • auto-created

To create a new indicator:
  1. Go to Incidents & Events > Indicators.

  2. Click Create New.

  3. From the Indicator dropdown, select the indicator type.

  4. In the Indicator Value field, enter the appropriate value for the indicator type (IP, URL, or domain).

  5. Click Create.

To edit an indicator:
  1. Go to Incidents & Events > Indicators.

  2. Select and indicator, and click Edit.

  3. Update the indicator.

  4. To save the changes, click Edit.

To delete an indicator:
  1. Go to Incidents & Events > Indicators.

  2. Select and indicator, and click Delete.

  3. To confirm the deletion, click OK.

To enrich an indicator:
  1. Go to Incidents & Events > Indicators.

  2. Select and indicator, and click Enrich.

    Alternatively, you can double-click the indicator or right-click the indicator and click Enrich.

    The Enrich pane displays.

  3. Review the details in the Enrich pane.

  4. Click Save Enrichment or Cancel according to the review.

    The indicator will only be processed and enriched after clicking Save Enrichment.