Fortinet white logo
Fortinet white logo

User Guide

FortiSIEM Manager Incidents

FortiSIEM Manager Incidents

When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are 2 primary views:

  • Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
  • List View: This tabular view enables the user to search incidents and take actions. (List by Time, Device, Rule, Category (FortiAI))

To interact with an incident, see Acting on Incidents.

FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Lookups Via External Websites.

FortiSIEM Manager Incidents

FortiSIEM Manager Incidents

When a correlation rule triggers, an incident is created in FortiSIEM. This section describes how to view and manage Incidents in FortiSIEM. There are 2 primary views:

  • Overview: This view provides a "top down" view of the various types of Incidents and impacted hosts.
  • List View: This tabular view enables the user to search incidents and take actions. (List by Time, Device, Rule, Category (FortiAI))

To interact with an incident, see Acting on Incidents.

FortiSIEM can cross-correlate incident data and perform lookups on selected external ticketing/work flow systems. See Lookups Via External Websites.