Fortinet white logo
Fortinet white logo

User Guide

Overview

Overview

FortiSIEM allows two types of searches:

  • Real time search: This enables you to search the events in real time as they are being ingested and before they are stored in the event database. You cannot do Group By operations in Real time Search.

  • Historical search: This enables you to search events that are already stored in event database.

You can create the following types of searches:

  • Pure Event Search: Searches on Events, e.g. Top Destination IP addresses in Inbound Firewall Denies.

  • Pure CMDB Search: Searches on CMDB data stored in PostGreSQL, e.g. All Windows Servers where MS SQL Server process is running.

  • Lookup Table Searches: Searches by combining Events and Lookup Tables.

  • Combined Event and CMDB Searches

    • Nested Searches by combining Event Searches with CMDB Reports, e.g. All Windows Servers in CMDB that did not report in last 1 hour.

    • Event Searches using DeviceToCMDBAttr Function that can refer to CMDB Device Properties, e.g. All Critical Windows Servers in CMDB that did not report in last 1 hour, or All Windows Servers located in San Jose that did not report in last 1 hour.

Overview

Overview

FortiSIEM allows two types of searches:

  • Real time search: This enables you to search the events in real time as they are being ingested and before they are stored in the event database. You cannot do Group By operations in Real time Search.

  • Historical search: This enables you to search events that are already stored in event database.

You can create the following types of searches:

  • Pure Event Search: Searches on Events, e.g. Top Destination IP addresses in Inbound Firewall Denies.

  • Pure CMDB Search: Searches on CMDB data stored in PostGreSQL, e.g. All Windows Servers where MS SQL Server process is running.

  • Lookup Table Searches: Searches by combining Events and Lookup Tables.

  • Combined Event and CMDB Searches

    • Nested Searches by combining Event Searches with CMDB Reports, e.g. All Windows Servers in CMDB that did not report in last 1 hour.

    • Event Searches using DeviceToCMDBAttr Function that can refer to CMDB Device Properties, e.g. All Critical Windows Servers in CMDB that did not report in last 1 hour, or All Windows Servers located in San Jose that did not report in last 1 hour.