Hi All,
I am running CMDB Reports toward incidents I need to get incident triggered for example 4 days ago what attribute i should use and the values of those attributes
I was trying to configure one see the image below
#CMDB
thanks, on advance
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @mohamed44 ,
When working with FortiSIEM time in searches or API queries is in Epoch time. Have a look at the article https://community.fortinet.com/t5/FortiSIEM/Technical-Tip-How-to-purge-events-for-an-organization-fr... - Section Date.
Also if I can ask what version of FortiSIEM are you using? I don't remember Incident First Seen as variable, I think the variable is Incident First Occurrence Time.
Regards,
S
Created on 07-01-2024 06:22 AM Edited on 07-01-2024 07:01 AM
Dear @sioannou I'm working on FortiSIEM version 7.1.3, and I notice that the attribute called:
Incident First Occurrence Time
but it won't appear while running or configuring CMDB report for incident
BR
update I tried to use the epoch time but did not work
Hi @mohamed44 ,
CMDB reports are purely for CMDB (devices under monitoring), they do not contain any information on Incidents nor can you create a report for Incidents under CMDB Reports.
If you are looking into developing a new Incident Report than the best option is to go to Resources-> Reports -> Incidents, find a relevant report load it into analytics, make necessary customisations and then save it as a new report for future reference.
When working with analytics if you are looking for information not in the Events (i.e. System Event Category = 0), then you need to specify the System Event Category as shown https://help.fortinet.com/fsiem/7-1-1/Online-Help/HTML5_Help/Event-categories-handling.htm
Regards,
S
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.