Managing indicators
Indicators can be found in Incidents & Events > Indicators. This pane contains a chart view and table view of the indicators.
There are three charts in the chart view:
-
Indicator Type
-
Reputation
-
Enrichment Status
By default, all three charts are displayed. From the Show Charts dropdown, you can toggle which charts display. You can also toggle Show Charts to hide all charts, when needed.
Select a value in any of the charts to apply the filter to all charts and the table view. To remove the filter, click the chart title.
The following actions are available in the toolbar:
Action |
Description |
---|---|
Create New | Create a new indicator. Once the indicator is created, the Source column will display the admin that created it. |
Edit |
Edit the indicator. |
Delete |
Delete the indicator. |
Enrich |
Enrich the indicator. For more information, see Indicator enrichment. |
The following columns are available in the table view:
Column |
Description |
---|---|
Indicator | The indicator name. |
Type |
The indicator type:
|
Rating Confidence |
The rating confidence from FortiGuard. |
Reputation |
The reputation from VirusTotal:
|
Enrichment Status |
The enrichment status:
|
Source |
The source of the enrichment:
|
To create a new indicator:
-
Go to Incidents & Events > Indicators.
-
Click Create New.
-
From the Indicator dropdown, select the indicator type.
-
In the Indicator Value field, enter the appropriate value for the indicator type (IP, URL, or domain).
-
Click Create.
To edit an indicator:
-
Go to Incidents & Events > Indicators.
-
Select and indicator, and click Edit.
-
Update the indicator.
-
To save the changes, click Edit.
To delete an indicator:
-
Go to Incidents & Events > Indicators.
-
Select and indicator, and click Delete.
-
To confirm the deletion, click OK.
To enrich an indicator:
-
Go to Incidents & Events > Indicators.
-
Select and indicator, and click Enrich.
Alternatively, you can double-click the indicator or right-click the indicator and click Enrich.
The Enrich pane displays.
-
Review the details in the Enrich pane.
-
Click Save Enrichment or Cancel according to the review.
The indicator will only be processed and enriched after clicking Save Enrichment.