Fortinet white logo
Fortinet white logo

User Guide

Viewing Rules

Viewing Rules

FortiSIEM includes a large set of rules for Availability, Performance, Change, Security, and Beaconing groups in addition to the rules that you can define for your system.

Complete these steps to view all system and user-defined rules:

  1. Go to Resources > Rules.
  2. Use the All/System/User drop-down menu of the Rules list pane to filter rules by Organization.
  3. Select any rule in the Rules list to view related information in the sidebar.
    All rules have two information tabs:
    TabsDescription
    SummaryThis tab provides an overview of the rule logic, its status, and notification settings.
    Test Results

    If you are testing a rule, you can view the results here.

    Note: Active rules cannot be tested. You must deactivate a rule before testing.

Viewing Rules

Viewing Rules

FortiSIEM includes a large set of rules for Availability, Performance, Change, Security, and Beaconing groups in addition to the rules that you can define for your system.

Complete these steps to view all system and user-defined rules:

  1. Go to Resources > Rules.
  2. Use the All/System/User drop-down menu of the Rules list pane to filter rules by Organization.
  3. Select any rule in the Rules list to view related information in the sidebar.
    All rules have two information tabs:
    TabsDescription
    SummaryThis tab provides an overview of the rule logic, its status, and notification settings.
    Test Results

    If you are testing a rule, you can view the results here.

    Note: Active rules cannot be tested. You must deactivate a rule before testing.