Discovery Range Definition Options
When you set the range definition for your discovery processes, several options are available for how you want the discovery process to run.
Option | Description | ||||||||
Discovery Type | Four types of scans are available for the discovery process:
|
||||||||
Root IPs | For Smart Scan only, provide the root IPs from which you want the Smart Scan to start. | ||||||||
Include/Exclude
Domains (AWS Only) |
Enter the domains you want to include or exclude from the discovery process. | ||||||||
Include/Exclude
Zones (AWS Only) |
Enter the zones you want to include or exclude from the discovery process. | ||||||||
Include/Exclude
Ranges |
Enter the IP addresses or host names you want to include or exclude from the discovery process. | ||||||||
Include/Exclude
Device Types |
Click the Edit icon to select devices that you want to include or exclude from the discovery process. Note that if you have entries for both of these option, the discovery process will prioritize included devices over excluded ones. | ||||||||
Do Not Ping
Before Discovery |
To save time, FortiSIEM first attempts to reach devices by ping before initiating discovery. You should select this option if ping has been disabled for your network, otherwise discovery will fail. | ||||||||
Ping Only
Discovery |
Select this option if you are only interested in discovering whether a device or service is up or down. | ||||||||
Only Discover
Devices not in CMDB |
If you select this option, discovery will only find those devices whose IP addresses do not match the address of any device in CMDB. To make an exception to this rule, specify a list of IP addresses in the Exclude Ranges field. The primary use case for this is for indirect device discovery such as VCenter-based VM discovery, or WLAN controller-based access point discovery. By specifying the VCenter IP address in the Exclude Ranges field, new guest VMs can always be discovered even if the VCenter is already in the CMDB. | ||||||||
Include
Powered Off VMs |
By default, only powered on VMs are discovered. | ||||||||
Include VM
Templates |
By default, VM templates are not discovered. | ||||||||
Discover
Routes |
Selected by default, if you clear this option then discovery will not use the route table to find next hop devices. This can be useful if your network includes border routers, which can significantly impact the time required for the discovery process. |