FortiSIEM Charts and Views

FortiSIEM provides a variety of charts and maps to better help you understand and analyze your incident data. You can access these charts and views from the widget dashboard settings (see Modifying widget information display) or by clicking the TABLE or drop-down icon in the ANALYTICS page (see Viewing Historical Search Results).

Chart/View

Description

Display Settings

Requirements

Table

Displays data in a tabular format.

You can choose to display the bar chart (Show Bar), the event type (Show Event Type), and the count (Count). Set the colors for the bar chart or reverse the color map.

None

Link Graph

Displays source, event, and destination relationships. Source nodes appear in light blue, Event nodes are color coded by their severity if event attribute "Event Severity Category" exists in the Display Fields on Table view. A node can be clicked and dragged to be repositioned. If a node can be represented by a recognizable device type from FortiSIEM, the appropriate icon will be displayed, otherwise a default monitor icon will appear.

The Rows and Total number represent the number of data items in the table view, not the number of nodes. For example, one representation will consist of 3 nodes (source, event, destination), but if all the data items share the same source, event, and destination, only three nodes will appear.

 

Click on any node and the following options appear:

  • Quick Info - Select to show more information about the selected node.

  • Add <object> to Filter - Adds the data from the selected node to a filter.

Select the Source, Event, and Destination from the drop -down lists.

Auto Layout attempts to show all nodes in an optimal manner. To disable, deselect the Auto Layout checkbox.

A source and destination are required.

Bar Chart

Displays data similar to a bar chart.

Select the Aggregate Field (Column) to display and their colors. You can also reverse the color map.

At least one numeric column is required.

Chord Chart

A graphical method of displaying the inter-relationships between data in a matrix. The data is arranged radially around a circle with the relationships between the data points typically drawn as arcs connecting the data.

Select the incident Source, Target, and Value from the drop-down lists.

At least two key columns and one numeric column are required.

Choropleth Chart

A thematic map in which areas are shaded or patterned in proportion to the measurement of the statistical variable being displayed on the map.

Select the Location and Value from the drop-down lists.

At least one numeric column is required. Configure Google Maps API Key in ADMIN > Settings > System > UI See UI Settings.

Cluster Bubble Chart

You can use a bubble chart instead of a scatter chart if your data has three data series that each contain a set of values. The sizes of the bubbles are determined by the values in the third data series.

Select the Column from the drop-down list.

At least one numeric column is required.

Donut Chart

Displays data similar to a pie chart.

Select the Aggregate Field (Column) to display since the report may have multiple Aggregate Fields.

At least one numeric column is required.

GEO Map Chart

Displays the IP addresses in a geographic map.

Public or private IP addresses with location defined in ADMIN > Settings > Discovery > Location. See Setting Location.

At least one numeric column is required.

Heat Map Chart

Displays two event attributes and a numerical aggregate value.

Select the Heat map coordinates X and Y, and an associated Value.

At least two key columns and one numeric column are required.

Sankey Chart

A specific type of flow diagram, in which the width of the arrows is shown proportionally to the flow quantity.

Select the Source, Target, and Value from the drop-down lists.

At least two key columns and one numeric column are required.

Scatter Plot Chart

Plots two aggregate fields.

Select two aggregate fields, X and Y. Select the Size of the sample.

At least two numeric columns are required.

Sunburst Chart

Visualizes hierarchical data, depicted by concentric circles. The circle in the center represents the root node, with the hierarchy moving outward from the center.

Select the Rank1, Rank2, Rank3 and Count from the drop-down lists.

Only one column can be used in one rank.

Tree Map Chart

Displays columns in a Tree Map.

Select the Tree Map Ranks and the Count attributes from the drop-down lists.

Only one column can be used in one rank.