Fortinet white logo
Fortinet white logo

User Guide

FortiSIEM Manager Incidents

FortiSIEM Manager Incidents

When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are 2 primary views:

  • Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
  • List View: This tabular view enables the user to search incidents and take actions. (List by Time, Device, Incident)

To interact with an incident, see Acting on Incidents.

FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Lookups Via External Websites.

FortiSIEM Manager Incidents

FortiSIEM Manager Incidents

When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are 2 primary views:

  • Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
  • List View: This tabular view enables the user to search incidents and take actions. (List by Time, Device, Incident)

To interact with an incident, see Acting on Incidents.

FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Lookups Via External Websites.