FortiSIEM Discussions
mohamed44
New Contributor II

Watch Lists & Lookup Tables

Hi all,

What is the difference between the Watch lists & Lookup Table

thanks on advance

#Watch lists

#Lookup tables

Muhammed
Muhammed
1 REPLY 1
premchanderr
Staff
Staff

Hi @mohamed44 ,

 

Both are totally different. 

Lookup Table is a function used in Analytics to display desired result based on key and values. Non Key Column is not supported here. This is mainly used in reporting. 

 

Watchlists need not by a keyvalue, you can simply add any list of IPs, string etc in watchlist.
Also watch list can be dynamically created from raw logs or triggered rules.  Watch list can be used in rules, report etc

 

Related Documentation:

 https://help.fortinet.com/fsiem/7-0-3/Online-Help/HTML5_Help/appendix-functions-lookup-table.htm?Hig...

https://help.fortinet.com/fsiem/7-0-3/Online-Help/HTML5_Help/Watch_list.htm 

Regards,
Prem Chander R
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"