FortiSIEM Manager Incidents
When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are 2 primary views:
- Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
- List View: This tabular view enables the user to search incidents and take actions. (List by Time, Device, Incident)
To interact with an incident, see Acting on Incidents.
FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Lookups Via External Websites.