Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Automated Case Management and Assignment in FortiSIEM 7.2

Fortinet
05/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


management and assign cases in the automated fashion. To begin, let's login to Fortisim, go to CMDB, then expand Users tab. Here I have pre-created three analyst groups named as Escalations, Level 1 and Level 2. Each with varying technical expertise of analysts. Next, we'll navigate to the Admin tab, under Settings, select Case Management. Click New in the General tab to create a new policy, provide a policy name and define the service level agreement and escalation procedures. In the Auto Assignment section, select how cases will be assigned, by role, team member or manually. I will choose random assignment within team members. Finally, use the Permissions tab to control case status. You can also customize notifications based on subject, recipients and delivery method. The Auto Close option allows cases to be closed automatically. Next, I will create a new policy named Level 2 Analyst Policy. The only change will be in the Auto Assignment, where cases will be assigned solely to the team lead. All other settings remain unchanged. To create an automation policy, navigate to the General section, under Settings, create a new policy named Level 1 Team. In the Rules section, specify the relevant categories for the analyst group. I'm assigning Availability and Performance related cases. Configure the policy to generate a case when an incident occurs. Then select the previously defined case management policy that determines case management based on the policy configuration. Recall that we established different analyst groups with varying expertise. For this policy, I will choose Level 1 Analyst and then Level 2 Analyst and then click Save. I will create another new policy named Level 2 Team to handle medium and high severity cases. I will choose the Changes and Security categories in the Rules section, so cases related to these areas are automatically assigned. In the Action field, I will modify the Create case when incident is created. This automation policy will handle change and security incidents, which require advanced skills. Therefore, I will assign it to the Level 2 Analyst group. For case management, I will use the previously created Level 2 Analyst policy that automatically assign cases to the team leads within that group. Enable both rules to activate the automation policy. Next, we'll navigate to Case tab. Fortisim's Case Management Overview page provides analysts with a comprehensive understanding of case trends. By analyzing open cases, severity levels, and escalated cases, analysts can identify patterns, prioritize incidents, and assess overall security posture. Additionally, Key Performance Indicators KPIs offer insights into the efficiency of the incident response process, from event detection to case creation, and highlight the source of the incident generation. Go to Cases tab and select List View. In a few minutes, you will see cases automatically assigned to analysts according to the policy. The incident summary identifies unusual service installations on domain control servers. The case has been automatically assigned to a Level 2 Analyst based on its severity. By diving deeper into this case, analysts can view related incidents, hosts, observables, and tactics and techniques used. This information is invaluable for understanding the attack. Clicking Explore reveals details about each linked incident on this case. Mitre mappings help identify related incidents and the techniques used to gain access. Finally, the Investigate tab provides a chronological timeline for the incident, aiding in understanding the attack's progression. This demonstrates Fortisim's robust case management capabilities, from initial assignment to thorough investigation. Thanks for watching.

TL;DR

  • FortiSIEM 7.2 introduces automated case management that assigns incidents to analyst groups based on configurable policies matching case categories to team expertise levels.
  • Administrators can define SLAs, escalation procedures, and assignment methods (random, team lead, or manual) through case management policies with customizable notifications.
  • Automation policies route incidents by category—availability and performance to Level 1, security and changes to Level 2—ensuring appropriate skill matching.
  • The Case Management Overview provides KPIs tracking incident response efficiency, while investigation tools include MITRE ATT&CK mappings and chronological attack timelines.

Automated Case Assignment and Policy Configuration

This demonstration walks through FortiSIEM 7.2's automated case management capabilities, showing how security operations teams can streamline incident handling through policy-based assignment. The workflow begins with creating analyst groups organized by expertise level—Escalations, Level 1, and Level 2—each designed to handle cases matching their technical capabilities. Administrators can configure case management policies that define service level agreements, escalation procedures, and assignment methods including random distribution among team members or direct assignment to team leads. The automation policies tie incident categories to specific analyst groups, ensuring availability and performance issues route to Level 1 analysts while security and change-related incidents requiring advanced skills automatically escalate to Level 2 teams.

Case Investigation and MITRE ATT&CK Integration

Beyond assignment automation, FortiSIEM provides analysts with comprehensive investigation tools once cases are created. The Case Management Overview page surfaces key performance indicators tracking incident response efficiency from event detection through case creation. When analysts drill into individual cases, they gain visibility into related incidents, affected hosts, observables, and the tactics and techniques employed by attackers. MITRE ATT&CK mappings help identify attack patterns and techniques used to gain access, while a chronological timeline in the Investigate tab reveals the attack's progression. This end-to-end workflow—from automated triage to deep investigation—demonstrates how FortiSIEM aims to reduce manual overhead while maintaining thorough incident analysis capabilities.

Chapters

0:00 - Introduction to Automated Case Management
0:15 - Creating Analyst Groups
0:31 - Configuring Case Management Policies
1:34 - Building Automation Policies
3:01 - Case Overview and KPIs
3:38 - Case Investigation and MITRE Mappings

Key Quotes

0:00 "In this demo, we introduce a new feature in Fortisim 7.2, where you can automate case management and assign cases in the automated fashion."
2:37 "This automation policy will handle change and security incidents, which require advanced skills. Therefore, I will assign it to the Level 2 Analyst group."
3:05 "Fortisim's Case Management Overview page provides analysts with a comprehensive understanding of case trends."

Categories:
  • » Webinar Library » Fortinet
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Demo
  • Technical Deep Dive
  • SIEM case management
  • incident response automation
  • security operations workflows
  • analyst tiering
  • MITRE ATT&CK integration
  • SLA management
  • incident escalation
  • security analytics
  • SOC efficiency
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Automated Case Management and Assignment in FortiSIEM 7.2

              Industry Events (Sponsor Hosted)

              • Aug
                13

                Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                08/13/202612:00 PM ET
                • Aug
                  19

                  Becoming Agent Ready with Cyera: Essential Strategies and Insights

                  08/19/202612:00 PM ET
                  More events

                  Upcoming Webinar Calendar

                  • 08/13/2026
                    12:00 PM
                    08/13/2026
                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                    https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                  • 08/19/2026
                    12:00 PM
                    08/19/2026
                    Becoming Agent Ready with Cyera: Essential Strategies and Insights
                    https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                  • 09/02/2026
                    12:00 PM
                    09/02/2026
                    Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                    https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                  • 09/30/2026
                    04:00 AM
                    09/30/2026
                    AI Command Center: Optimizing Visibility and Control in Your Operations
                    https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                  • 11/19/2026
                    01:00 PM
                    11/19/2026
                    360View: Govern, Secure & Recover Your Microsoft 365 Environment
                    https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                  Truth in IT
                  • Sponsor
                  • About Us
                  • Terms of Service
                  • Privacy Policy
                  • Contact Us
                  • Preference Management
                  Desktop version
                  Standard version