28 August 2024 version 2024.8.0
- New functionality
- Improved functionality
- Other improvements
- New detection rules and observations
- Resolved issues
New functionality
Share investigations
Users with multiple accounts can share investigations in their primary account with users in their secondary account. Sharing an investigation will allow all users with access to the secondary account to see and make changes to the investigation. Once the investigation is shared, it cannot be undone. For more information, see Share investigations.
Detection assignment
You can now assign active detections to a user from the Detections Table, Triage Device, and the Triage Rules page. For more information, see Assigning detections.
To assign a detection to a user from the Detections Table, click the actions menu and select Assign Detection.
You can bulk assign and unassign detections from the tools menu at the top-left of the table.
You can also assign a detection from the actions menu in the Triage Rules page.
Similarly, you can assign a detection from a rule in the events table in the Triage Device page. Select an impacted device, and then select a rule and click the Assign Detection button.
The following new columns were added to the Detections Table : Assigned Comment, Assignee, Current Assign Time, and Initial Assign time. An Assigned / Unassigned value was also added to the table filter. You can filter the table based on the user the detection was assigned to.
Improved functionality
Account region
The account region now appears at the top of the settings menu and sensor provisioning page.
The region can be either US or EU.
Events table
When you show all columns in the Events table, you now have the option to quickly adjust the column width to the widest cell in the table. To adjust the column width, right-click the column header and select either Fit Width or Default Width.
Observations widget
The Observations widget in the default dashboard has been enhanced to make it easier to filter and view observations. The filter toggles have been enlarged to make them easier to see and click. The widget also displays all the observations. The total number of observations is displayed at the top of the widget and a scroll bar has been added to scroll through the list. You can also Hide All Graphs and toggle the graphs you want to see.
Manage Annotations
The tables in the Manage Annotations page have been enhanced. When you add entities, FortiNDR Cloud will validate the field when you click Save.
The search function has also been improved to support searching any text in the Annotation Name and Annotation Description columns. In previous versions, search was limited to an exact match of the annotation name.
When you hover over an annotation in the Event table, it will show a tooltip with the annotation name and description. When you click the annotation, all the annotation details are displayed in a pop-up window.
User management
The Roles column in the Users page, now mirrors the roles and icons in the user details pane. When you download the table as a CSV file, the roles are assigned a column for each role.
Triage devices
The Triage Devices page has been improved, with a scrollable Impacted Devices panel at the left side of the page. The device detections table at the bottom of the page has also been replaced with a new scrollable table. All of the filters have been moved to the top of the page.
When you click the link in the Detection Rule column the rule details are displayed. and assign a detection. You can use the pane to assign a detection to a user.
Other improvements
Detections table
The can now use any column header in the Detections Table to sort the detections. This enhancement is only available in the Detections Table.
Search Timeline
The Search Timeline feature has been renamed Private Search.
Integrations guides
The integrations guides have been consolidated onto a dedicated page.
To access the page, in the Portal, click Portal Guides > Integrations.
You can also access the page by clicking the Integration Guides button in the Fortinet Document Library.