Fortinet white logo
Fortinet white logo

Administration Guide

Advanced Data

Advanced Data

The Advanced Data area presents statistics about the selected entity in the application list. The information that displays varies, depending on the entity selected (application or version).

Application Advanced Data

When an application is selected in the application list, the ADVANCED DATA area displays the following information for it:

Application information

The APPLICATION INFO area displays summary information about the selected application.

In the Process Names field, a separate row appears for each application that shares the same vendor, product and version properties. The Process Names field displays the full file path for each such application.

You can click the three dots next to the Process names field to navigate to the Threat Hunting window for that process name or hash, or to explore the hash in VirusTotal, as shown below:

Application Usage

The APPLICATION USAGE area displays details about usage of the selected application.

This area shows the number of connections (communication sessions) per day. The top line shows the total number of devices within the organization on which the selected application is installed.

Each row below the underline represents a different Collector Group, and shows the number of devices in the organization in that Collector Group.

Each person icon represents 10% of the total devices in the organization/Collector Group. Black icons represent devices that communicate externally using the selected application, and gray icons represent devices that did not communicate externally using the application.

You can hover over the people icons to see the percentage of devices that communicate externally per day using the selected application. For example, the figure below shows that only 3% of the devices in the organization have the selected application installed.

Click the More link to open the following window, in which you can view additional details about the selected application.

Click the Export to Excel button in this window to export application usage information to Excel.

Destinations

The Destinations area shows the destinations to which the selected application communicated (Allowed) or attempted to communicate (Denied).

Each row shows the IP address, connection time and country of the destination.

By default, this area displays the five most-recent destinations. Click the More link to open the following window, which displays the last 50 destinations.

Version Details

The Version Details area displays the action defined for the application in each policy, plus its vulnerability details and affected destinations.

Advanced Data

Advanced Data

The Advanced Data area presents statistics about the selected entity in the application list. The information that displays varies, depending on the entity selected (application or version).

Application Advanced Data

When an application is selected in the application list, the ADVANCED DATA area displays the following information for it:

Application information

The APPLICATION INFO area displays summary information about the selected application.

In the Process Names field, a separate row appears for each application that shares the same vendor, product and version properties. The Process Names field displays the full file path for each such application.

You can click the three dots next to the Process names field to navigate to the Threat Hunting window for that process name or hash, or to explore the hash in VirusTotal, as shown below:

Application Usage

The APPLICATION USAGE area displays details about usage of the selected application.

This area shows the number of connections (communication sessions) per day. The top line shows the total number of devices within the organization on which the selected application is installed.

Each row below the underline represents a different Collector Group, and shows the number of devices in the organization in that Collector Group.

Each person icon represents 10% of the total devices in the organization/Collector Group. Black icons represent devices that communicate externally using the selected application, and gray icons represent devices that did not communicate externally using the application.

You can hover over the people icons to see the percentage of devices that communicate externally per day using the selected application. For example, the figure below shows that only 3% of the devices in the organization have the selected application installed.

Click the More link to open the following window, in which you can view additional details about the selected application.

Click the Export to Excel button in this window to export application usage information to Excel.

Destinations

The Destinations area shows the destinations to which the selected application communicated (Allowed) or attempted to communicate (Denied).

Each row shows the IP address, connection time and country of the destination.

By default, this area displays the five most-recent destinations. Click the More link to open the following window, which displays the last 50 destinations.

Version Details

The Version Details area displays the action defined for the application in each policy, plus its vulnerability details and affected destinations.