Incidents and Cases Advanced Operations
FortiSIEM enables you to perform the following advanced operations:
- Changing the Home Country
- Searching Incidents
- Tuning Incidents via Exceptions
- Tuning Incidents via Modifying Rules
- Tuning Incidents via Drop Rules
- Tuning Incidents by Adjusting Thresholds
- Clearing Incidents
- Adding Comments or Remediation Advice to an Incident
- Remediating an Incident
- Notifying an Incident via Email
- Creating New Rules
- Creating a FortiSIEM Ticket
- Creating a Ticket in External Ticketing System
Changing the Home Country
Many rules and reports use the My Home CMDB Object as defined in RESOURCES > Country Groups > My Home. By default, it is set to United States of America.
For details on changing this, see here.
Searching Incidents
If you want to search for specific incidents, go to INCIDENTS > List > Actions > Search. A Search Windows appears on left. First, select the Time Window of interest. Then by clicking on any of the criteria, you can see the current values. You can select values to see matches incidents in the right pane.
For details about Searching Incidents, see here.
Tuning Incidents via Exceptions
If you do not want a rule to trigger for a specific Incident Attribute, then you can create an exception.
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incident shows in the right pane.
- Highlight the Incident.
- Click Actions > Edit Rule Exception.
- Enter the exception criteria – attribute based or time-based.
For details about Tuning Incidents via Exceptions, see here.
Tuning Incidents via Modifying Rules
Sometimes modifying the rule is a better idea than creating exceptions. For example, if you do not want a rule to trigger for DNS Servers, simply modify the rule condition by stating something like “Source IP NOT CONTAIN DNS Server”. To do this:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incident shows in the right pane.
- Highlight the Incident.
- Click Actions > Edit Rule.
- Edit the Rule.
If it is a System Rule, then you must save it as a User Rule. Deactivate the old System Rule and activate the new User Rule.
For details, see here.
Tuning Incidents via Drop Rules
Sometimes the rule can be prevented from triggering by dropping the event from rule considerations. There are two choices - (a) store the event in database but not trigger the rule or (b) drop the event completely.
To do this:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incident shows in the right pane.
- Highlight the Incident.
- Click Actions > Create Event Dropping Rule.
- Specify event drop criteria and action. Events can be dropped on certain parsed fields (like Reporting/Source/Destination IP and Regex filter on the content).
For details, see here.
Tuning Incidents by Adjusting Thresholds
Some performance rules are written using global thresholds, for example - the Rule “High Process CPU: Server” uses the global threshold “Process CPU Util Critical Threshold” defined in ADMIN > Device Support > Custom Property.
You have two choices – (a) modify the global threshold or (b) modify the threshold for a specific device or a group of devices. If you change the global threshold, then the threshold will change for all devices.
To modify the global threshold, follow these steps:
- Go ADMIN > Device Support > Custom Property.
- Select the property and click Edit.
- Enter the new value and click Save.
For details, see here.
To modify the threshold for one device, follow these steps:
- Go to CMDB.
- Select the device and click Edit.
- In the Properties tab, enter the new value and click Save.
To modify the threshold for a group of devices, repeat the above step for all devices.
Clearing Incidents
In some cases, the Incident may not be happening anymore as the exception condition was corrected.
To clear one or more Incidents:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incidents show in the right pane.
- Highlight the Incidents.
- Click Actions > Clear Incident.
- Enter Reason and click OK.
For details, see here.
Adding Comments or Remediation Advice to an Incident
To add a comment to an Incident:
- Go to INCIDENTS > List view.
- Search the Incident or make sure that Incidents show in the right pane.
- Highlight the Incidents.
- Click Actions > Edit Comment.
- Enter the Comment and click OK.
For details, see here.
Sometimes, it is necessary to add Remediation advice for the recipient of an Incident, so he can take some action to remediate the Incident. This has to be done by editing the Rule.
- Go to RESOURCES > Rules.
- Select a Rule and click Edit.
- Enter Remediation Note text and click Save.
For details, see here.
The Remediation text can be added to the Incident Notification email template.
For details, see here.
Remediating an Incident
You can use the following commands to enable Windows Remote Management (WinRM) and set authentication on the target Windows Servers. See Remediations for information on adding, editing, and deleting a remeditation from the FortiSIEM UI.
In the remediation script:
- When you initiate the WinRM session, set
transport
parameter tossl
. - Set the
server_cert_validation
option accordingly. If you do not need to validate the certificate, set toignore
. For example:session = winrm.Session(enforceOn, auth = (user, password), transport="ssl", server_cert_validation = "ignore")
In the target Windows server:
Note: You might need to disable Windows Firewall before running remediation.
- Create the self-signed certificate in the certificate store, for example:
New-SelfSignedCertificate -CertStoreLocation Cert:\LocalMachine\My -DnsName "mySubjectName.lan"
where
Cert:\LocalMachine\My
is the location of the certificate store andmySubjectName.lan
is the subject alternate name extension of the certificate. - Create an HTTPS listener, for example:
winrm create winrm/config/Listener?Address=*+Transport=HTTPS '@{Port ="5986";Hostname="{your host name}"; CertificateThumbprint="{CertificateThumbprint}"}'
- Start the WinRM service and set the service
startup
type toauto-start
. Thequickconfig
command also configures a listener for the ports that send and receive WS-Management protocol messages using either HTTP or HTTPS on any IP address.winrm quickconfig -transport:https
- Validate the WinRM service configuration and Listener.
- Check whether basic authentication is allowed, for example:
winrm get winrm/config/service
- Check whether a listener is running, and verify the default ports, for example:
winrm get winrm/config/listener
- Check whether basic authentication is allowed, for example:
Remediation can be done either on an ad hoc basis (for example, user selects an Incident that has already occurred to Remediate) or using a Notification Policy where the system takes the Remediation action when Incident happens. First, make sure the Remediation script for your scenario is defined. Check the existing Remediation scripts in ADMIN > Settings > General > Notification Policy > Remediation settings. If your device is not in the list, add the needed Remediation script.
To set ad hoc remediation:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incidents show in the right pane.
- Highlight the Incident you want to remediate (you can remediate only one Incident at a time)..
- Click Actions > Remediate Incident.
- In the Run Remediation dialog box:
- Select the script in the Remediation drop-down list that you want to run.
- Select the role that the script will run on from the Run On drop-down list.
- Open the Enforce On drop-down list to choose which devices the remediation script will run on. In the Run Remediation dialog box, open the Device tree. Select individual devices and shuttle them to the Selections column. (You can choose only individual devices; you cannot choose device groups.)
- Click Run in the Run Remediation dialog box.
For details, see here.
To set policy-based remediation:
- Go to ADMIN > Settings > General > Notification Policy.
- Click New.
- Under Action, click the edit icon next to Run Remediation/Script.
- In the Notification Policy - Define Script/Remediation dialog box click New.
- In the dialog box tha topens click either Legacy Script or Remediation:
- Legacy Script:
- Enter the name and path to the script in the Script field.
- Select the role the script will run on from the Run On drop-down list.
- Remediation:
- Select a remediation script from the Script drop-down list.
- Select the role that the script will run on from the Run On drop-down list.
- Open the Enforce On drop-down list to choose which devices the remediation script will run on. In theNotification Policy - Define Script/Remediation - Enforce On dialog box, open the Device tree. Select individual devices and shuttle them to the Selections column. (You can choose only individual devices; you cannot choose device groups.)
- Legacy Script:
- Click Save.
For details, see here.
To see the Notification history of an Incident:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incidents show in the right pane.
- Highlight the Incidents.
- Click Actions > Show Notification History.
For details, see here.
Notifying an Incident via Email
Notifying an Incident can be done either on ad hoc basis (for example - user selects an Incident that has already occurred to notify) or using a Notification Policy where the system takes the notification action when Incident happens.
First, make sure that Email Server has been properly defined in ADMIN > Settings > Email > Email Settings.
FortiSIEM has a built-in Incident Notification Email template. If you want a different one, please define it under ADMIN > Settings > Email > Incident Email Template.
For details, see here.
To set ad hoc notifications:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incidents show in the right pane.
- Highlight the Incidents.
- Click Actions > Notify via Email.
- Choose Receive Email Address and Email Template.
- Click Send.
For details, see here.
For Policy based Notification
To send policy-based notifications:
- Go to ADMIN > Settings > General > Notification Policy.
- Click New.
- Specify the Incident Filter Conditions (Severity, Rules, Time Range, Affected Items, Affected Organizations) carefully to avoid excessive emails.
- Under Action, click Send Email/SMS to Target Users.
- Enter Email Address or Users from CMDB.
- Click Save.
For details, see here.
To see the Notification history of an Incident:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incidents show in the right pane.
- Highlight the Incidents.
- Click Action > Show Notification History
For details, see here.
Creating New Rules
Sometime, you may want to create a new rule from scratch.
For details, see here.
Creating a FortiSIEM Ticket
First make sure that:
- Ticket’s assigned user is in CMDB
- Assigned user’s Manager that is going to handle escalation is in CMDB
- A Ticket Escalation Policy is defined
For adding users see Advanced Operations > Creating System users.
For defining ticket escalation policy, see here.
To create a FortiSIEM ticket:
- Go to INCIDENTS > List view.
- Search the Incident (Actions > Search) or make sure that Incidents show in the right pane.
- Highlight the Incidents.
- Click Actions > Create Ticket.
- Click Save
Note that you can put multiple Incidents on one ticket or add an Incident to an existing ticket.
For details, see here.
Creating a Ticket in External Ticketing System
First, define an Incident Outbound Integration Policy by visiting ADMIN > Settings > General > External Integration.
For details, see here.
Then set the Incident Outbound Integration Policy in Notification Policy Action:
- Go to ADMIN > Settings > General > Notification Policy.
- Click New.
- Specify the Incident Filter Conditions (Severity, Rules, Time Range, Affected Items, Affected Organizations) carefully to avoid excessive emails.
- Under Action, click Invoke an Integration Policy.
- Choose the Integration Policy.
- Click Save.
For details, see here.
To update external ticket state in FortiSIEM:
- Define an Incident Inbound Integration Policy by visiting ADMIN > Settings > General > External Integration.
- Select the Policy and click Schedule to run the Incident Inbound Integration Policy.
For details, see here.