Skip to main content
labsession101
Visitor III
October 12, 2023
Solved

FortiSIEM fine tuning

  • October 12, 2023
  • 5 replies
  • 2829 views

Hi,

Any tips or documentation for fine tuning the fortiSIEM rules/incident alert?
Trying to improve or add fine tuned rules / incident alerts we are getting from the fortiSIEM.

 

Thank you.

    Best answer by Secusaurus

    Hi labsession101,

     

    Are you using a multi tenant version or enterprise version? In a multi tenant environment you need to consider that fine-tuning could (but does not need to) be different for each tenant.

     

    Anyways, we are using the following processes here:

    • Avoid making exceptions. E.g.: If a rule should not match on a specific device, either the device is in the "wrong" CMDB group or there are more general reason for not using the rule here, instead of excluding a single device.
      In our experience, the more exceptions you create, the more difficult it is to reproduce why something happened but we did not see an Incident
    • Copy a rule, disable it and refine the copy. If you need to get back to the original one, you can also get the original idea again.
    • (generally for rules) Avoid inserting single values, like an exact IP address. Try to use CMDB/resource values as often as possible to be flexible for other tenants
    • We do always write down changes to rules in a separate document/wiki. Ca. once a month, we review all the refined rules, if the refinement still makes sense.

    Does this help? Or are you looking for specific examples of refinements here?

     

    Best,

    Christian

    5 replies

    Secusaurus
    Contributor III
    October 12, 2023

    Hi labsession101,

     

    Are you using a multi tenant version or enterprise version? In a multi tenant environment you need to consider that fine-tuning could (but does not need to) be different for each tenant.

     

    Anyways, we are using the following processes here:

    • Avoid making exceptions. E.g.: If a rule should not match on a specific device, either the device is in the "wrong" CMDB group or there are more general reason for not using the rule here, instead of excluding a single device.
      In our experience, the more exceptions you create, the more difficult it is to reproduce why something happened but we did not see an Incident
    • Copy a rule, disable it and refine the copy. If you need to get back to the original one, you can also get the original idea again.
    • (generally for rules) Avoid inserting single values, like an exact IP address. Try to use CMDB/resource values as often as possible to be flexible for other tenants
    • We do always write down changes to rules in a separate document/wiki. Ca. once a month, we review all the refined rules, if the refinement still makes sense.

    Does this help? Or are you looking for specific examples of refinements here?

     

    Best,

    Christian

    NSE8 | Fortinet Advanced MSSP Partner
    labsession101
    Visitor III
    October 12, 2023

    Hi Chris,

    Thank for your inputs. Will take these into consideration.
    This is an enterprise deployment only so no other tenants needs to be considered.

    So far what we have tried is to clone the default rule and edit it per our requirement.

    was looking for other way or better way making fine tuning,

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!