Skip to main content
acronymm
Visitor III
May 19, 2025
Solved

Seeking Guidance on Mapping Device Relationships in FortiSIEM for Network Diagram

  • May 19, 2025
  • 1 reply
  • 748 views

Hello FortiSIEM Community,

I’m managing a #FortiSIEM instance with a large number of diverse devices (e.g., firewalls, servers, switches) added for monitoring. To improve analysis and incident response, I want to create a network diagram that visually maps these devices and their relationships (e.g., traffic flows, dependencies).

Questions:

  1. Built-in Visualization Tools: Does FortiSIEM offer native features (like topology maps, CMDB views, or dashboards) to auto-generate such diagrams? If yes, how do I leverage them?
  2. Manual Relationship Mapping: If no built-in tools exist, what methods or data sources (e.g., CMDB entries, event logs, traffic patterns) can I use to quickly identify device relationships and dependencies? For example, specific reports, queries, or MITRE ATT&CK rule correlations?

Any examples, scripts, or step-by-step guides would be incredibly helpful! Thanks in advance for your expertise.

Best answer by Secusaurus

Hi @acronymm,

 

FortiSIEM is not a network management tool. Therefore, visualization for traffic flow or device dependencies is not a core task here.

You can define all kind of relations in the CMDB (within a device or using the Applications & Business Services) which then can result in meaningful reports or can be used in search queries in Analytics view - but the output will always be tables.

As you mentioned the MITRE matrix: Have a look at the different incident views. There is a view that shows that correlation. However, from our experience, this is more a marketing view than something an Analyst would use in daily doing.

 

The connection between incidents, though, can be visualized. Use the "Investigation" view for that one. By clicking on one of the bubbles (either incident or asset), you can then uncover other relations which are pulled from this or other incidents. However, this view is not designed for showing non-incident-related information - so, if there is no incident connecting two assets, there will not be a connection between those.

 

Do you have an example on what you like to achieve?

 

Best,

Christian

1 reply

Secusaurus
Contributor III
May 22, 2025

Hi @acronymm,

 

FortiSIEM is not a network management tool. Therefore, visualization for traffic flow or device dependencies is not a core task here.

You can define all kind of relations in the CMDB (within a device or using the Applications & Business Services) which then can result in meaningful reports or can be used in search queries in Analytics view - but the output will always be tables.

As you mentioned the MITRE matrix: Have a look at the different incident views. There is a view that shows that correlation. However, from our experience, this is more a marketing view than something an Analyst would use in daily doing.

 

The connection between incidents, though, can be visualized. Use the "Investigation" view for that one. By clicking on one of the bubbles (either incident or asset), you can then uncover other relations which are pulled from this or other incidents. However, this view is not designed for showing non-incident-related information - so, if there is no incident connecting two assets, there will not be a connection between those.

 

Do you have an example on what you like to achieve?

 

Best,

Christian

NSE8 | Fortinet Advanced MSSP Partner
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!