Fortinet white logo
Fortinet white logo

User Guide

Detections Table

Detections Table

The Detections Table is where you can view all detections. Whereas the Triage Rule and Detections Triage views show detections by rule or device, the Detections Table shows detections by rule and device over time. By default, the table displays detections for the last two weeks. A color-coded bar at the left side of the table indicates active and resolved detections. A green bar indicates an active detection. A red bar indicates a resolved detection.

To access the Detections Table:
  • Go to Detections > Detections Table.

  • On the Dashboard:

    • In the MITRE ATT&CK widget, click a bar in the chart.
    • In the Resolved Detections widget, click Total or click a data point in the chart.

Filtering events

By default, the Detections Table displays detections by all severities and detection statuses for the previous two weeks ending on the current date. You can use any column header to sort the detections. Filters allow you to view detections for a specific IP, refine the list by Severity and Detection Status. You can also toggle between table and graph view.

1

Device IP to search Enter the IP of a specific device.

2

Time range

Click to open the date picker.

Use the calender to set the start and end date or select an option from the Quick Ranges (Last Hour to Last 90 days).

Click Resolution Date to show all detections resolved within the time range. This will disable the buttons in the Severity area.

3

Severity

Select High (H), Medium (M), or Low (L).

4

Detection Status
All

Detections that were active during time range and are still active or resolved now.

For example, a detection that was active on May 5 and resolved on May 10 is counted as ALL.

Active Detections that were active during time range and are still active.
Resolved Detections that were active during time range and are resolved now.

5

Additional filters
Category Select a category from the list. See, Detections > Rule Categories.
Created By Select and account that created the rule from the list.
MITRE ATT&CK Select the detection by behavior from the list. See, MITRE ATT&CK.

Assigned to

Select a user assigned to a detection.

Resolved by

Select a user from the list.

Resolution

Select All, True Positive: Mitigated, True Positive: No Action, False Positive, or Unknown.

Sensor Select a sensor from the list.
Rule Name Select a parameter used for the detection from the list.
Confidence

Select All, High (H), Medium (M), or Low (L).

Muted Select All, Unmuted or Muted. See, Muting rules.
Disabled Select All, Enabled or Disabled. See, Disabling rules.

Assigned

Select All, Assigned, or Unassigned.

6

Columns selectors

Individual Columns

Select one of the following options:

  • Show all columns
  • Hide All Columns
  • Reset to default
  • Select columns to show or hide in the table.

Column Profiles

Select one of the following options:

  • Click a profile in the list to view the layout.
  • Save the profile
  • Create a new profile.

For more information, see Creating column profiles

7

CSV Click to export the list as a CSV file.

8

Table View Click for table view (default).

9

Graph View Click to open the Visualizer.

10

Actions menu

Select one of the following options:

  • Create Rules

  • Manage Rules

  • Muted Devices

  • Excluded devices

  • Manage Subscriptions

Detections Table

Detections Table

The Detections Table is where you can view all detections. Whereas the Triage Rule and Detections Triage views show detections by rule or device, the Detections Table shows detections by rule and device over time. By default, the table displays detections for the last two weeks. A color-coded bar at the left side of the table indicates active and resolved detections. A green bar indicates an active detection. A red bar indicates a resolved detection.

To access the Detections Table:
  • Go to Detections > Detections Table.

  • On the Dashboard:

    • In the MITRE ATT&CK widget, click a bar in the chart.
    • In the Resolved Detections widget, click Total or click a data point in the chart.

Filtering events

By default, the Detections Table displays detections by all severities and detection statuses for the previous two weeks ending on the current date. You can use any column header to sort the detections. Filters allow you to view detections for a specific IP, refine the list by Severity and Detection Status. You can also toggle between table and graph view.

1

Device IP to search Enter the IP of a specific device.

2

Time range

Click to open the date picker.

Use the calender to set the start and end date or select an option from the Quick Ranges (Last Hour to Last 90 days).

Click Resolution Date to show all detections resolved within the time range. This will disable the buttons in the Severity area.

3

Severity

Select High (H), Medium (M), or Low (L).

4

Detection Status
All

Detections that were active during time range and are still active or resolved now.

For example, a detection that was active on May 5 and resolved on May 10 is counted as ALL.

Active Detections that were active during time range and are still active.
Resolved Detections that were active during time range and are resolved now.

5

Additional filters
Category Select a category from the list. See, Detections > Rule Categories.
Created By Select and account that created the rule from the list.
MITRE ATT&CK Select the detection by behavior from the list. See, MITRE ATT&CK.

Assigned to

Select a user assigned to a detection.

Resolved by

Select a user from the list.

Resolution

Select All, True Positive: Mitigated, True Positive: No Action, False Positive, or Unknown.

Sensor Select a sensor from the list.
Rule Name Select a parameter used for the detection from the list.
Confidence

Select All, High (H), Medium (M), or Low (L).

Muted Select All, Unmuted or Muted. See, Muting rules.
Disabled Select All, Enabled or Disabled. See, Disabling rules.

Assigned

Select All, Assigned, or Unassigned.

6

Columns selectors

Individual Columns

Select one of the following options:

  • Show all columns
  • Hide All Columns
  • Reset to default
  • Select columns to show or hide in the table.

Column Profiles

Select one of the following options:

  • Click a profile in the list to view the layout.
  • Save the profile
  • Create a new profile.

For more information, see Creating column profiles

7

CSV Click to export the list as a CSV file.

8

Table View Click for table view (default).

9

Graph View Click to open the Visualizer.

10

Actions menu

Select one of the following options:

  • Create Rules

  • Manage Rules

  • Muted Devices

  • Excluded devices

  • Manage Subscriptions