Device view
FortiNDR Cloud continuously collects data on the devices present in a network. This data is collected on a per sensor basis, since multiple sensors may report the same IP address, either due to re-use of IP space within a single environment, or through traffic from an IP crossing multiple monitoring points.
You can use Device View to:
-
Quantify FortiNDR Cloud sensor visibility coverage over time.
-
Verify that FortiNDR Cloud sees both internal and external traffic from network devices.
Viewing visible devices
To view the visible devices:
-
Click the gear icon at the top-right of the page and select Sensors.
-
In the toolbar, click Visible Devices . The page is organized into three sections:
All Subnets Search Enter a subnet or prefix to view a specific device. Date Click to open the date picker to view devices within a specif date range. Additional Filters Click the filter icon to view devices by sensor and Internal and External traffic directions. Devices by Subnet Highlight by Select External Traffic % or Internal Traffic % to change the colors in the box-plot chart to show the percentage of assets.
Use this view to verify FortiNDR Cloud is seeing both internal (East-West) and external (North-South) traffic on a specific subnet.
View -
By Subnet: This the default view.
-
Over Time: Shows how many devices were seen within the selected subnet over time. This graph is if sensor coverage is experiencing issues or to debug problems with missing events for a certain time period.
Box-plot chart Click the box-plot chart to drill down into the selected subset of the network. # SUBNETS SEEN BETWEEN YYYY-MM-DD AND YYYY-MM-DD Shows either a summary of subnets or a list of discrete devices. This table is useful for reviewing the traffic on a per device basis.
-