Fortinet white logo
Fortinet white logo

User Guide

FortiSIEM Manager

FortiSIEM Manager

FortiSIEM Manager can be used to monitor and manage multiple FortiSIEM instances. The FortiSIEM Manager needs to be installed on a separate Virtual Machine and requires a separate license.

Note: Only FortiSIEM Manager and FortiSIEM Supervisor instances 6.5.0+ are supported.

FortiSIEM Manager provides the following functionalities:

  • Each FortiSIEM Instance needs to register to the FortiSIEM Manager. After successful registration, a 2-way HTTP(S) communication channel is set up between each Instance and the Manager.
  • Incidents, License and Health information will be forwarded from each FortiSIEM instance to the FortiSIEM Manager. Incidents are forwarded in near-real time, Health information forwarded once every minute, and License information forwarded once every hour.
  • FortiSIEM Manager retains Health information for the last 1 day. FortiSIEM Manager also stores Incidents and the latest License information in local PostGreSQL database. The number of incidents stored depends on the size of the local PostGreSQL database. Raw events are not stored in FortiSIEM Manager. When the user visits the Triggering Event tab on the Incidents page, raw events are fetched on demand from the FortiSIEM Instance.
  • All Incident status changes in each FortiSIEM instance are forwarded to the FortiSIEM Manager. If you create a new rule or make changes to a rule in a FortiSIEM instance, the changes are forwarded to the FortiSIEM Manager.
  • From FortiSIEM Manager, you can do the following operations and the changes are propagated to the right FortiSIEM instance(s) with the right FortiSIEM Manager logged-in-user context:
    • Clear, Resolve and Add Comments to one or more Incidents
    • Disable one or more rules and change their severity.
    • Change the severity of an incident
    • Run FortiSOAR Playbooks and Connectors and update Incident Status and Comments
    • A one-click operation to log you into the appropriate FortiSIEM instance where an Incident occurred. This enables you quickly to investigate an Incident in depth.

Communication between FortiSIEM Manager and instances is via REST APIs over HTTP(S).

You have to upgrade FortiSIEM Manager first before upgrading all FortiSIEM Instances - this applies to both Content Update and Software Image Update.

For details in installing FortiSIEM Manager, see the VM or Hardware Installation Guides here.

For details on registering a FortiSIEM instance to the FortiSIEM Manager, see here.

For viewing health and license information in FortiSIEM Manager, see here.

The FortiSIEM Manager provides the following tools.

FortiSIEM Manager

FortiSIEM Manager

FortiSIEM Manager can be used to monitor and manage multiple FortiSIEM instances. The FortiSIEM Manager needs to be installed on a separate Virtual Machine and requires a separate license.

Note: Only FortiSIEM Manager and FortiSIEM Supervisor instances 6.5.0+ are supported.

FortiSIEM Manager provides the following functionalities:

  • Each FortiSIEM Instance needs to register to the FortiSIEM Manager. After successful registration, a 2-way HTTP(S) communication channel is set up between each Instance and the Manager.
  • Incidents, License and Health information will be forwarded from each FortiSIEM instance to the FortiSIEM Manager. Incidents are forwarded in near-real time, Health information forwarded once every minute, and License information forwarded once every hour.
  • FortiSIEM Manager retains Health information for the last 1 day. FortiSIEM Manager also stores Incidents and the latest License information in local PostGreSQL database. The number of incidents stored depends on the size of the local PostGreSQL database. Raw events are not stored in FortiSIEM Manager. When the user visits the Triggering Event tab on the Incidents page, raw events are fetched on demand from the FortiSIEM Instance.
  • All Incident status changes in each FortiSIEM instance are forwarded to the FortiSIEM Manager. If you create a new rule or make changes to a rule in a FortiSIEM instance, the changes are forwarded to the FortiSIEM Manager.
  • From FortiSIEM Manager, you can do the following operations and the changes are propagated to the right FortiSIEM instance(s) with the right FortiSIEM Manager logged-in-user context:
    • Clear, Resolve and Add Comments to one or more Incidents
    • Disable one or more rules and change their severity.
    • Change the severity of an incident
    • Run FortiSOAR Playbooks and Connectors and update Incident Status and Comments
    • A one-click operation to log you into the appropriate FortiSIEM instance where an Incident occurred. This enables you quickly to investigate an Incident in depth.

Communication between FortiSIEM Manager and instances is via REST APIs over HTTP(S).

You have to upgrade FortiSIEM Manager first before upgrading all FortiSIEM Instances - this applies to both Content Update and Software Image Update.

For details in installing FortiSIEM Manager, see the VM or Hardware Installation Guides here.

For details on registering a FortiSIEM instance to the FortiSIEM Manager, see here.

For viewing health and license information in FortiSIEM Manager, see here.

The FortiSIEM Manager provides the following tools.