CMDB
FortiSIEM enables you to perform the following CMDB advanced operations.
- Discovering Users
- Creating FortiSIEM Users
- Setting Eternal Authentication
- Setting 2-Factor Authentication
- Assigning FortiSIEM Roles to Users
- Creating Business Services
- Creating Dynamic DMDB Groups
- Setting Device Geo-Location
- Creating CMDB Reports
Discovering Users
Users can be discovered via LDAP, OpenLDAP, or they can be added manually. Discovering users via OpenLDAP or OKTA are similar.
To discover users in Windows Active Directory, discover the Windows Domain Controller:
- Go to Admin > Setup > Credentials.
- Click + to create an LDAP discovery credential by entering the following in the Access Method Definition dialog box:
- Name for the credential
- Device Type as "Microsoft Windows Server 2012 R2"
- Access Protocol as "LDAP"
- Used For as "Microsoft Active Directory"
- Enter the Base DN and NetBios Domain
- Test the LDAP Credentials.
- Run discovery.
- Go to CMDB > Users.
- Click the "Refresh" icon on left panel and see the users displayed on the right panel.
To add users manually:
- Go to CMDB > Users.
- Click New and add the user information.
For details about Discovering Users, see here (Refer to the table by searching: Credentials for Microsoft Windows Server)
For details about Adding Users, see here.
Creating FortiSIEM Users
To create users that access FortiSIEM:
- Login as a user with "Full Admin" rights.
- Create the user in CMDB.
- Set a password – after logging in, the user can set a new password.
- Select the user and click Edit.
- Select System Admin and enter the following:
- Authentication Mode - "Local" or "External"
- Enterprise case - select the Role
- Service Provide Case - select the Role for each Organization
For details about creating users, see here.
To change the password:
- Login as the user.
- Click the "User Profile" icon on the top-right corner.
- Click Save.
Setting External Authentication
FortiSIEM users can be authenticated in two ways:
- Local authentication – user credentials are stored in FortiSIEM
- External authentication – user credentials are stored in an external database (AAA Server or Active Directory) and FortiSIEM communicates with the external database to authenticate the user
Step 1: Set up an Authentication Profile
- Login as a user with Full Admin rights.
- Create an authentication profile by visiting Admin > Settings > General > External Authentication.
- Click +.
- Provide the following information in the External Authentication Profile dialog box:
- Enter a Name for the profile
- Select an Organization from the drop-down list
- Set Protocol appropriately (for example, LDAP, LDAPS, or LDAPTLS for Active Directory)
- Enter the IP/Host and Port number
- Make sure the credentials are defined in Admin > Setup > Credentials.
- Select the entry and click Test to ensure it works correctly.
Step 2: Attach the Authentication Profile to the user
- Select the user under CMDB > User and click Edit.
- Select System Admin and click the edit icon.
- Set Mode to "External" and set the Authentication Profile created.
For details about Setting up Authentication Profiles, see here.
For details about Editing Users, see here.
Setting 2-Factor Authentication
FortiSIEM supports Duo as 2-factor authentication for FortiSIEM users:
Step 1: Set up an Authentication Profile
- Login as a user with Full Admin rights.
- Create an authentication profile by visiting Admin > Settings > General > External Authentication:
- Set Protocol to "Duo"
- Make sure the credentials are defined in Admin > Setup > Credentials
- Select the entry and click Test to make sure it works correctly
Step 2: Attach the Authentication Profile to the user
- Select the user CMDB > Users and click Edit
- Select System Admin and click the edit icon
- Set Mode to "External" and set the Authentication Profile created
For details about Setting up Authentication Profiles, see here.
For details about Editing Users, see here.
Assigning FortiSIEM Roles to Users
FortiSIEM allows the admin user to create Roles based on what data the user can see what the user can do with the data. To set up Roles:
Step 1: Create a Role of your choice
- Login as a user with Full Admin rights.
- Go to Admin > Settings > Role > Role Management.
- Make sure there is a Role that suits your needs. If not, then create a new one by clicking + and entering the required information. You can also Clone an existing Role and make the changes.
Step 2: Attach the Role to the user
- Select the user CMDB > Users and click Edit.
- Select System Admin and click the edit icon.
- Set Default Role:
- Enterprise case – select the Role
- Service Provide Case – select Role for each Organization
For details about Setting up Roles, see here.
For details about Editing Users,see here.
Creating Business Services
Business Service is a smart grouping of devices. Once created, incidents are tagged with the impacted Business Service(s) and you can see business service health in a custom Business Service dashboard.
For details about creating a Business Service, see here.
For details about setting up Dynamic Business Service, see here.
For details about viewing Business Service health, see here.
Creating Dynamic CMDB Groups and Business Services
CMDB Groups are a key concept in FortiSIEM. Rules and Reports make extensive use of CMDB Groups. While inbuilt CMDB Groups are auto-populated by Discovery, user-defined ones and Business Services are not. You can use the Dynamic CMDB Group feature to make mass changes to user-defined CMDB Groups and Business Services.
To create Dynamic CMDB Group Assignment Rules:
- Login as a user with Admin tab modification rights.
- Go to Admin > Settings > Discovery > CMDB Groups.
- Click +.
- Enter CMDB Membership Criteria based on Vendor, Model, Host Name and IP Range.
- Select the CMDB group (Groups) or Business Services (Biz Services) to which the Device would belong if the criteria in Step 3 is met.
- Click Save.
You can now click Apply to immediately move the Devices to the desired CMDB Groups and Business Services. Discovery will also honor those rules – so newly discovered devices would belong to the desired CMDB Groups and Business Services.
For details about Setting up Dynamic CMDB Groups and Business Services, see here.
Setting Device Geo-Location
FortiSIEM has location information for public IP addresses. For private address space, you can define the locations as follows:
- Login as a user with Admin tab modification rights.
- Go to Admin > Settings > Discovery > Location.
- Click +.
- Enter IP/IP Range.
- Specify the Corresponding Location for the IP address Range.
- Select Update Manual Devices if you want already discovered device locations to be updated.
- Click Save.
You can now click Apply to set the geo-locations for all devices matching the IP ranges.
For details about Setting Device Location, see here.
Creating CMDB Reports
If you want to extract data from FortiSIEM CMDB and produce a report, FortiSIEM can run a CMDB Report and display the values on the screen and allows you to export the data into a PDF or CSV file.
For details about Creating CMDB Reports, see here.