Unified incident response page
This information is also available in the FortiAnalyzer 7.6 Administration Guide: |
The Incidents page has undergone a complete transformation, becoming the central command center for SOC analysts. This streamlined hub empowers analysts to monitor, investigate, and take decisive actions from a single, intuitive interface.
Key enhancements include:
-
Prioritization at a glance: Interactive charts at the top provide immediate insights, allowing analysts to prioritize and filter incidents with ease.
-
Actionable intelligence: The incident table has been meticulously reorganized, placing vital information, including new columns like Incident Name, Indicators, and Incident Reporter, front and center for efficient decision-making.
The Incidents & Events > Incidents pane now includes the following tabs:
-
Incidents
-
MITRE ATT&CK®
-
MITRE ATT&CK® ICS
For more information about the MITRE ATT&CK® in FortiAnalyzer, see the FortiAnalyzer Administration Guide.
The Incidents tab now includes three charts above the table view:
-
Severity
-
Status
-
Category
By default, the Show Charts toggle is enabled. You can select which charts appear by selecting them in the Show Charts dropdown.
You can also hide all the charts by disabling the Show Charts toggle.
Click a section of a chart to filter the charts and the table by that information. You can apply multiple filters across the charts. Once filtered, a filter icon appears next to the chart title; click the filter icon to remove the filter. You can also filter the table by the time frame dropdown in the toolbar.
The following columns have been added to the incidents table view:
-
Incident Name
-
Indicators
-
Incident Reporter
You can enter a name when creating an incident. Incident names are automatically generated for auto-created incidents.
For more information about indicators, see New indicators page.
The following new actions are available in the toolbar and the right-click menu from Incidents & Events > Incidents > Incidents.
Action |
Description |
---|---|
Enrich |
Enrich the indicators associated with the incident. For more information, see Indicator enrichment. |
Export |
Export the incident as HTML or PDF. For more information, see Export incident. |
You can also export the incident list from Incident & Events > Incidents > Incidents. Click More > Export Table as CSV. The exported CSV file includes all the columns and details displayed in the filtered GUI table.