Fortinet white logo
Fortinet white logo

User Guide

Device view

Device view

FortiNDR Cloud continuously collects data on the devices present in a network. This data is collected on a per sensor basis, since multiple sensors may report the same IP address, either due to re-use of IP space within a single environment, or through traffic from an IP crossing multiple monitoring points.

You can use Device View to:

  • Quantify FortiNDR Cloud sensor visibility coverage over time.

  • Verify that FortiNDR Cloud sees both internal and external traffic from network devices.

Viewing visible devices

To view the visible devices:
  1. Click the gear icon at the top-right of the page and select Sensors.

  2. In the toolbar, click Visible Devices . The page is organized into three sections:

    All Subnets
    Search Enter a subnet or prefix to view a specific device.
    Date Click to open the date picker to view devices within a specif date range.
    Additional Filters Click the filter icon to view devices by sensor and Internal and External traffic directions.
    Devices by Subnet
    Highlight by

    Select External Traffic % or Internal Traffic % to change the colors in the box-plot chart to show the percentage of assets.

    Use this view to verify FortiNDR Cloud is seeing both internal (East-West) and external (North-South) traffic on a specific subnet.

    View
    • By Subnet: This the default view.

    • Over Time: Shows how many devices were seen within the selected subnet over time. This graph is if sensor coverage is experiencing issues or to debug problems with missing events for a certain time period.

    Box-plot chart Click the box-plot chart to drill down into the selected subset of the network.
    # SUBNETS SEEN BETWEEN YYYY-MM-DD AND YYYY-MM-DD

    Shows either a summary of subnets or a list of discrete devices. This table is useful for reviewing the traffic on a per device basis.

Device view

Device view

FortiNDR Cloud continuously collects data on the devices present in a network. This data is collected on a per sensor basis, since multiple sensors may report the same IP address, either due to re-use of IP space within a single environment, or through traffic from an IP crossing multiple monitoring points.

You can use Device View to:

  • Quantify FortiNDR Cloud sensor visibility coverage over time.

  • Verify that FortiNDR Cloud sees both internal and external traffic from network devices.

Viewing visible devices

To view the visible devices:
  1. Click the gear icon at the top-right of the page and select Sensors.

  2. In the toolbar, click Visible Devices . The page is organized into three sections:

    All Subnets
    Search Enter a subnet or prefix to view a specific device.
    Date Click to open the date picker to view devices within a specif date range.
    Additional Filters Click the filter icon to view devices by sensor and Internal and External traffic directions.
    Devices by Subnet
    Highlight by

    Select External Traffic % or Internal Traffic % to change the colors in the box-plot chart to show the percentage of assets.

    Use this view to verify FortiNDR Cloud is seeing both internal (East-West) and external (North-South) traffic on a specific subnet.

    View
    • By Subnet: This the default view.

    • Over Time: Shows how many devices were seen within the selected subnet over time. This graph is if sensor coverage is experiencing issues or to debug problems with missing events for a certain time period.

    Box-plot chart Click the box-plot chart to drill down into the selected subset of the network.
    # SUBNETS SEEN BETWEEN YYYY-MM-DD AND YYYY-MM-DD

    Shows either a summary of subnets or a list of discrete devices. This table is useful for reviewing the traffic on a per device basis.