Hello community, I am new to FortiSIEM, I want to build a rule to detect new devices in my network, I had the idea to create like a list containing MAC addresses and a rule to check each time if a mac is in that list if not it will trigger an incident and add the mac address to the list (if you are familiar with qradar it is like a reference set), the problem is I don't know if that is applicable also in FortiSIEM or there is another approach to solve the problem??? any idea is appreciated, thank you in advance.
Solved! Go to Solution.
Hello again,
I found a workaround to implement this using just the SIEM. Here is what I did:
First, I performed a search and grouped all MAC addresses found in the SIEM over the last 7 days.
I sanitized the list and added it to the SIEM as a watch list by importing a CSV file.
Then, I created a rule to check whether the newly collected MAC addresses are on that list or not. If a MAC address is not on the list, it triggers an incident and adds that MAC address to the list.
I hope this can help anyone trying to implement the same thing. I am open to any further development of the context.
Have a good day.
Hi
I don't have idea how can do this with SIEM, but I know that is easily done with a NAC solution.
Thank you for your reply.
Hello again,
I found a workaround to implement this using just the SIEM. Here is what I did:
First, I performed a search and grouped all MAC addresses found in the SIEM over the last 7 days.
I sanitized the list and added it to the SIEM as a watch list by importing a CSV file.
Then, I created a rule to check whether the newly collected MAC addresses are on that list or not. If a MAC address is not on the list, it triggers an incident and adds that MAC address to the list.
I hope this can help anyone trying to implement the same thing. I am open to any further development of the context.
Have a good day.
Hi
Thanks for sharing.
Nice job! I love the idea, and I see how much we can do unimaginable tricks with SIEM.
You can mark your response as solution.
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.