Fortinet white logo
Fortinet white logo

User Guide

Filtering the Visualizer

Filtering the Visualizer

Use the filters at the top of the visualizer to change the content displayed in the canvas. Some filter options are static, others are dynamic based on the criteria selected elsewhere. When you modify the filter, the graph will be redrawn per the selected options.

Note

The Visualizer can retrieve up to 10,000 detections from the API regardless of the filter criteria.

Nodes

Use the Nodes filter to select the types of nodes to display. There are three types of nodes:

  • Indicators
  • Impacted Devices
  • Detectors
Note

When the Indicators option is selected, groups of indicators and impacted devices related to the same detector may be clustered together on the graph. While any combination can be selected, omitting Detection Name will usually result in a disjointed graph.

2021.6-viz-node-type

Detection Name

Use the Detection Name filter to hide or display detections. The detections displayed will depend on the other criteria selected in the report. Only the detections that are relevant to the rest of the criteria (such as Date Range, Device/Detections/Status, Severity) can be selected.

viz-rule-name

Date Range

Use the date-range selector to specify the date range to display.

viz-date-range

Filter by Status

You can refine the results in the Visualizer by Detection Status, Device Status, or Rule Status. Changing the status filters will initiate a new query to the Detections API and refresh the graph. All other filter changes will filter the existing data and redraw the graph.

viz-filter

Filtering the Visualizer

Filtering the Visualizer

Use the filters at the top of the visualizer to change the content displayed in the canvas. Some filter options are static, others are dynamic based on the criteria selected elsewhere. When you modify the filter, the graph will be redrawn per the selected options.

Note

The Visualizer can retrieve up to 10,000 detections from the API regardless of the filter criteria.

Nodes

Use the Nodes filter to select the types of nodes to display. There are three types of nodes:

  • Indicators
  • Impacted Devices
  • Detectors
Note

When the Indicators option is selected, groups of indicators and impacted devices related to the same detector may be clustered together on the graph. While any combination can be selected, omitting Detection Name will usually result in a disjointed graph.

2021.6-viz-node-type

Detection Name

Use the Detection Name filter to hide or display detections. The detections displayed will depend on the other criteria selected in the report. Only the detections that are relevant to the rest of the criteria (such as Date Range, Device/Detections/Status, Severity) can be selected.

viz-rule-name

Date Range

Use the date-range selector to specify the date range to display.

viz-date-range

Filter by Status

You can refine the results in the Visualizer by Detection Status, Device Status, or Rule Status. Changing the status filters will initiate a new query to the Detections API and refresh the graph. All other filter changes will filter the existing data and redraw the graph.

viz-filter