Work in the Forescout Console

The Forescout Console is the management application used for viewing information about endpoints and devices.

From the Forescout Console, you can view NAC compliance status, malicious intrusions, vulnerable endpoints, and real-time network inventories. In addition, the Console offers an extensive range of tools to analyze and manage these endpoints.

For the eyeSight Web Client, see Log In to the Forescout Console.

Console

Console

Forescout Console components

The following sections describe the key components of the Forescout Console window:

Title bar

The title bar displays the following information:

  • eyeSight device IP address or host name.
  • Login user name.
  • eyeSight device connection status with the Console.
  • Under certain circumstances, a user may have limited Scope access. Limited Scope access means that users cannot see or control many feature configurations in defined ranges and segments.

Under certain circumstances, a user may have limited Scope access. Limited Scope access means that users cannot see or control many feature configurations in defined ranges and segments. See Access to Network Endpoints - Scope for details.

The menu bar displays the Console menu options.

You can select More Space or Less Space in the Display menu to adjust the line spacing in the Console display.

Toolbar - Console views

Toolbar items provide quick access to important information and tools.

Endpoints detected on the network

To open the Home view, select the Home tab:

The Home view displays:

  • Extensive real-time information about endpoints detected on your network, for example, endpoint details learned by eyeSight, information about endpoint policy status, and eyeSight actions applied to endpoints. See Working with Forescout Detections for details.
  • The Forescout site map. The map, powered by Google®, provides at-a-glance, real-time information about endpoints across offices, cities, countries, and continents. See Working in the Site Map for details.

    Adjust the view for viewing preferences by using the toggle arrow on the edge of the Forescout Console pane.

Asset Inventory

The Asset Inventory presents a live display of network activity at multiple levels, for example, running processes and services, detected vulnerabilities, open ports, and logged in users.

To open the Asset Inventory view, select the Asset Inventory tab:

Use the Asset Inventory to:

  • Broaden your view of the network from endpoint-specific to activity-specific.
  • View endpoints that have been detected with specific attributes, whether or not they are policy-compliant.
  • Easily track network activity and elements.
  • Incorporate inventory detections into policies. For example, if you discover that network guests are running unauthorized processes on your network, you can create a policy that detects and halts these processes on guest machines.

For details, see Working with Asset Inventory Detections.

Threats

Threats view displays endpoints detected via Threat Protection policies. Create and edit Threat Protection Policies from this view. See Threat Protection for details. The Threats tab can be shown or hidden.

To show or hide the Threat Protection tab, select Tools > Options > Threat Protection, and then enable or disable the Show Threats View option.

Threat Protection tab

Threat Protection Tab

Customize the Threats View

Adjust the view for viewing preferences via the toggle arrows on the edge of the Forescout Console pane.

Policy management view

Use the tools in the Policy view to create, edit and manage policies.

To open the Policy Management view, select the Policy Management tab:

Dashboards (and Assets view)

Access the Dashboards (and Assets) view of the eyeSight Web Client. See Logging In to Forescout Web Portals for more information.

Dashboards display dynamic, at-a-glance information about:

  • Device visibility
  • Device compliance
  • Health monitoring
  • Forescout policy data, including custom policies

See Dashboards and Assets View for more information about these tools.

Assets portal, reports portal, and user portal builder

You can access the Assets Portal, Reports Portal and the User Portal Builder from the Forescout Console toolbar by clicking the ellipsis icon Ellipses icon.

Note: Users with an eyeSegment license can access Segmentation (eyeSegment application)  from the toolbar.
Ellipsis Icon
Ellipses icon
Access these options from the ellipsis drop-down menu:
Assets Portal, a web-based search and discovery tool that lets you leverage extensive network information regarding network assets. See Assets Portal for details.
Reports, to generate web-based reports. See Reports. For a full description of these reports, refer to the Reports Plugin Configuration Guide. .
User Portal Builder, a web-based portal for customizing the appearance of the Guest Management Portal, and web login pages for the HTTP Notification and HTTP Login. See The Forescout User Portal Builder for details.
Note: Users with an eyeSegment license can access Segmentation (eyeSegment application)  from the toolbar.
Marketplace Icon

Marketplace icon

Click the Marketplace icon to go to the Forescout Marketplace at marketplace.forescout.com to take advantage of all integrations from Forescout, our partners, the wider community, and third-party applications.
Options Icon
Options icon
Use the Optionsp window to define a wide range of system parameters and update parameters configured during the Appliance installation and initial setup.

Status bar

The status bar may display the following information:

Channel Connectivity Indicator
Channel Connectivity Indicator
The Channel Connectivity Indicator is displayed if:
There is a connectivity problem on one of the enabled channels.
No channels are enabled.
A new channel is discovered.
Forescout eyeSight continually searches for traffic on channels defined in the Channel Configuration dialog box. A tooltip indicates which event occurred.
Alarm Indicator
(Malicious Hosts Only)
Alarm Indicator
The alarm indicator flashes when new endpoint activity is detected. By default, the alarm blinks for two minutes each time a high severity event is detected.
Service Attack Indicator
Service Attack Indicator
The service attack indicator blinks when Forescout products detect a service attack. The indicator blinks until the service attack is viewed in the Current Service Attack dialog box. See Handling Service Attacks for details.
Connection Status Indicator
Connection Status Indicators
Indicates the connection status between Appliances and the Enterprise Manager. If an Appliance is disconnected, the red X mark is displayed. If a VMware VM is running as a shared resource, the blue I is shown.
Enforcement Mode
images/image27.png
If you set the system to the Partial Enforcement mode, the Enforcement indicator is displayed. The Partial Enforcement mode lets you monitor network traffic but limits your ability to respond to it. Specifically, the Threat Protection, HTTP Actions, and Virtual Firewall options are disabled. This mode is recommended for evaluation purposes only.
See Set the Enforcement Mode for details.
If the indicator reads High Activity Mode, Forescout products are responding to an extensive amount of traffic.
Updates
Updates icon
Indicates the availability of new updates of installed plugins and modules, based on detected versions installed on your eyeSight devices. Select the icon to view and install newer versions. See Base Modules, Content Modules, and (Undefined variable: product-names.eyeExtend) Modules for details.
High Availability Cluster Status
images/image52.PNGimages/image53.png
Indicates the status of a High Availability pair. Refer to the Forescout eyeSight Resiliency Solutions User Guide for more information about High Availability.
Date and Time Indicator
Date and Time Indicator
Indicates the current date and time according to your local time zone setting.

Search in the Forescout Console

Use the search tool Search tool to quickly access information from the Forescout Console, for example, in the Views pane, Detections pane, or the Modules pane. Items that match the search text appear as you type.

Where relevant, collapsed folders expand if the search item you entered is found in the folder. Some search bars can be hidden or displayed by clicking the pane header, for example, the Filters pane.

Note: Users with an eyeSegment license can access Segmentation (eyeSegment application)  from the toolbar.

Work in the Forescout Console site map

The Forescout Console site map, powered by Google®, provides at-a-glance, real-time information about endpoints across offices, cities, countries, and continents. You can toggle between a Satellite view and a Map view.

Site Map

Site Map

Endpoint information is displayed in the panes below the site map.

Endpoint Information in site map

Endpoint Information in Site Map

Use the map to get high-level status information for each site, such as:

  • Total number of devices
  • Non-compliant devices
  • Unmanaged devices
  • Devices without policies deployed
  • Blocked devices
  • Malicious devices
  • Number of online and offline devices
  • Number of corporate and guest devices Browser Requirements: The map runs on Internet Explorer 11.

Work with detections

The Console Home tab displays important details about endpoints detected by eyeSight policies. This information can include:

  • Device information, for example, IP addresses, MAC addresses, DNS host name or NetBIOS host name
  • Guest and compliance status
  • Switch related information, for example, the switch port to which the endpoint is connected
  • Endpoint and user identity information, for example, User Directory user name, email address, department
  • Information related to actions taken at the endpoint and notifications sent to network users
    Note: Users with an eyeSegment license can access Segmentation (eyeSegment application)  from the toolbar.

    The information displayed in the Detections pane varies depending on the selected Home view. See Home Views.

Deriving unique endpoints from observed addresses

eyeSight learns the IP and MAC addresses of endpoints and network nodes in the following ways:

  • By auditing network traffic.
  • By polling switches, controllers, domain controllers, and other network nodes.
  • When optional plugins are installed that use additional information sources, such as flow protocols eyeSight analyzes this information to identify unique endpoints, and to correlate IP and MAC addresses to each endpoint.
  • eyeSight data correlation logic uses only IPv4 addresses to identify unique endpoints. IPv6 addresses are not used to identify endpoints.
  • When no IPv4 address correlates to a unique MAC address, eyeSight lists this MAC-only endpoint with a placeholder IPv4 address in Console views.

    This discovery and correlation logic is unchanged when IPv6 addressable endpoints are supported.

  • Dual-stack endpoints are detected and displayed by their IPv4 addresses.
  • IPv6-only endpoints are detected by their MAC addresses, and displayed using a placeholder IPv4 address (as is done for MAC-only endpoints without an IPv4 address).

    For Console settings to enable detection of MAC-only and IPv6-only endpoints, see Work with Hosts without IPv4 Addresses.

    The Hosts indicator at the top right corner of the Detections pane displays the total number of endpoints detected for the folder or sub-folder you select. When there are a large amount of endpoints and it takes a long time to load the information to the Console, this indicator is updated to Showing X of X and displays the number of endpoints currently loaded out of the total detected.

About the Forescout Console details pane

When you select an endpoint in the Detections pane, extensive details appear in the Details pane.

Details pane

Details Pane

Forescout Console home views

The information displayed in the Detections pane varies depending on the selected Home view.

Forescout Console All Hosts view

The All Hosts view All Hosts View displays all endpoints that eyeSight detects. This includes endpoints that are not part of a particular policy.

Policy view

The Policy view images/image86.png displays endpoints detected as a result of policies created in the Policy Manager. Important detection statistics are provided. For example:

  • The policy that the endpoint matched and when it was detected
  • Machine information such as the IP address, MAC address, NetBIOS name and DNS name
  • Actions taken at the endpoint, for example, if the endpoint was blocked or if access was prevented to the Internet
  • User Directory information
  • Automated notifications sent to endpoint users
  • Information about endpoints that do not match the policy; endpoints that have been released from policy sanctions and endpoints that are pending inspection

Real-time policy status summary

You can view a real-time status summary for each policy. Policy status summaries are automatically updated in real time as the endpoint status changes.

Note: Hold your cursor over a policy folder to view the summary information.

Real-Time Policy Status Summary

Compliance view

The Compliance view images/image88.png displays endpoints that were detected in policies categorized as Compliance policies. By default, these include policies generated from Compliance templates.

Compliance categorization can also be configured in the Policy Manager.

Use this view to see information about the overall compliance status of endpoints included in such policies.

Select a specific endpoint to view a compliance summary for Compliance policies that inspected the endpoint.

The Compliance column entry in the Detections pane indicates whether the endpoint is overall compliant. If an endpoint is inspected by several compliance policies and is not compliant in one, the endpoint is not compliant.

images/image89.png

More specific compliance information is shown in the Details pane > Compliance tab, in the Forescout Compliance Center section. This information includes policy names, compliance issues, actions taken, remediation and last update time and the Status. If the Status indicates NA, the endpoint was not in the policy scope.

Corporate/guests view

The Corporate/Guests view images/image90.pngdisplays endpoints that were detected in policies categorized as Guest policies, including policies generated from the Corporate/Guest Control template. Categorization is performed in the Policy Manager.

This view displays information about the overall corporate or guest status of endpoints included in such policies.

History view

The History view images/image91.png displays a filtered snapshot of detection and action information from a previous period. You can view information about malicious endpoints, Service Attacks, and policy detections. When you select a History view, a set of filters are displayed at the top of the Detections pane.

History View

Work in the Detections pane

You can perform a variety of tasks from the Detections pane.

Track endpoints using the Detections pane filter

Use the Detections pane filter to quickly track endpoints of specific interest to you. Endpoints that meet the filter requirements appear as you type.

Detections Pane Filter

Note: The filter applies to all endpoints, but information may not appear if it is contained in hidden columns. Be sure to display columns that may contain relevant details.
Note: Restrict comma-separated search patterns in the Detections pane filter to no more than 20 patterns at a time. Searches query each column of each Host listed in the Detections pane, and extensive searches can lead to delays or service restarts. Search more effectively and reduce search times by narrowing searches using the Segments, Policies, and Group filters.

View table tooltip information

When you hover over an item in the table, a tooltip displays information regarding that item. For example, if you hold your cursor over the Action field, a tooltip displays detailed information regarding the action. Important troubleshooting information may be included. For example, an entry indicating that the endpoint has not been assigned to an Appliance and as a result is not monitored. For easier reading, select F2 to freeze the tooltip.

tooltip information

Configure the Detections pane columns

Default columns appear in the Detections pane with basic endpoint property details, actions taken at endpoints, and related information. The information varies according to the selected Home view. For each view, default information is displayed.

You can set change the layout and content of the columns in several ways.

Control endpoints from the Detections pane

Various options are available for controlling endpoints from the Detections pane. For example, you can:

  • Start and cancel Forescout actions on selected endpoints
  • Create endpoint exceptions
  • Recheck endpoint status
  • Clear property detections
  • Add a customized comment about the endpoint
  • Add the endpoint properties to a policy list

Work in the filters pane

The Filters pane provides tools that let you organize endpoints into logical categories, and then view them in the Detections pane per category.

This is important, for example, when managing networks with extensive detections.

Filters in Filter Pane

Several filter categories can be created.

Work with asset inventory detections

Select the Asset Inventory tab to view a live display of network activity at multiple levels, for example, running processes and services, detected vulnerabilities, open ports, and logged in users.

Use the Asset Inventory to:

  • Broaden your view of the network from endpoint-specific to activity-specific.
  • View endpoints that have been detected with specific attributes, whether or not they are policy-compliant.
  • Easily track network activity and elements.
  • Incorporate inventory detections into policies (black and white lists). For example, if you discover that network guests are running unauthorized processes on your network, create a policy that detects and halts these processes on guest machines.

The Asset Inventory is organized according to the following categories of network activity:

  • Classification
  • Microsoft Vulnerabilities detected
  • Classification (Advanced)
  • External Devices connected
  • Users
  • Applications Installed
  • Guest Registration
  • Switches integrated with the Forescout eyeSight
  • User Directory
  • Switch
  • Open Ports
  • Certain Windows, Linux and Macintosh activity and elements
  • Geolocation

You can maximize smooth tracking of this activity by customizing the inventory categories into sub-categories. For example, you may discover via the Asset Inventory that your network is working with a variety of authorized and unauthorized processes. If this is the case, you could create lists of authorized and unauthorized processes under the Process Running property folder or lists of Switch IP addresses per VLAN under the Switch folder.

Inventories only show endpoints that are currently online.

Asset Inventory activities are queried and refreshed every 23 hours. The refresh frequency can be modified from the Inventory Discovery rule. See Endpoint Discovery Rules for details.

Note: On a managed Appliance (connected to the Enterprise Manager), the Asset Inventory information is read-only, i.e., you cannot create, edit or remove lists.
Note: Users with an eyeSegment license can access Segmentation (eyeSegment application)  from the toolbar.

How the Asset Inventory is learned

The properties listed in the Asset Inventory view are learned using the following Forescout tools:

  • Inventory Discovery Rules
  • Detection Policies
    Note: Certain inventory items may be learned passively by eyeSight. This happens when the Appliance is installed and starts monitoring your network. However, this information may only be gathered from part of your network. It is recommended not to rely solely on this information when working with the Asset Inventory.

Filter the asset inventory view

The following options are available for filtering the Asset Inventory view.

Use the Search tool to filter the Asset Inventory display. The filter is applied automatically as you type, with the matching Asset Inventory items immediately shown in the Asset Inventory view. For example, display all open UDP ports by typing in UDP in the filter field.

images/image105.png

You can customize the Asset Inventory. For example, you may discover via the Asset Inventory that your network is working with a variety of authorized and unauthorized applications. In this case, you could create lists that itemize authorized and unauthorized applications under the Windows Applications Installed property folder or lists of Switch IP addresses per VLAN under the Switch folder. After you create lists, you can filter the Asset Inventory view according to those lists.

See Use Lists to Customize the Asset Inventory for details.

Asset inventory panes

The Asset Inventory is divided into the following areas:

  • The Views Pane lists inventory categories based on endpoint properties and property lists that you create.
  • The Detections Pane lists information about the inventory property category selected in the Views pane. For example, the number of endpoints running a specific process.
  • The Hosts Pane displays all endpoints that are detected with the selected inventory item. For example, the endpoint IP address, MAC address, connected switch port, or User Directory name.

Inventories only show information detected at online endpoints.

Views pane

The Views pane shows the Asset Inventory items that you can view.

images/image106.png

If plugins or (Undefined variable: product-names.eyeExtend) modules (Extended Modules) are installed, other items might be displayed, such as:

  • Classification Properties
  • Guest Registration
  • Windows machines
  • Function
  • User Directory
  • Microsoft Vulnerabilities detected
  • Operating System
  • Open Ports
  • Services Running
  • Vendor and Model
  • Windows Applications Installed
  • Switches integrated with the eyeSight
  • Network Function
  • External Devices connected
  • Macintosh machines
  • Advanced Classification Properties
  • Linux machines
  • Software Updates Missing
  • Suggested Function
  • Logged-in users
  • Applications Installed
  • Suggested Operating System
  • Operating system versions running
  • Users
  • Processes Running

You can create lists for each of the property categories shown in the view. For example, create an Unauthorized Processes Running List under the Processes Running category, and add all unauthorized processes detected at your network to it.

Detections pane

The Detections pane displays information about the property selected in the Views pane. Previously, the Detection pane read and showed only limited columns, resulting in missing data. Now, it reads all the columns and shows limited columns that were shown previously; however, you can add or remove additional columns for the selected view category.

images/image108.png

Inventory Property
(for example, Processes Running)
The property selected in the Views pane. Information in this column includes all the values for the related property. For example, if you select the Process Running property, this column shows all the processes currently running.
No. of Hosts
The number of endpoints currently detected with the selected property. For example, the number of endpoints running a process; the number of endpoints detected at switch IP address; the number of endpoints detected with vulnerabilities or the number of endpoints logged in as Windows users.
Last Update
The last date and time when the detection was made.
Last Host
The last endpoint where the activity was detected.
Lists
The lists to which the live inventory property was assigned. For example, the iexplore.exe process may be part of the White listed Server Processes list and the White listed Endpoint Processes list. See Use Lists to Customize the Asset Inventory for more information about creating lists.

Hosts pane

The Hosts pane displays the endpoints that have been detected for the Asset Inventory item selected. Previously, you would see missing data for several hardware properties; however, data for all properties can now be viewed. Use the tools available when working with endpoint detections to handle these endpoints. For example, you can assign actions to endpoints or drill down to get more detailed endpoint information. Use the search tool at the top of the pane to filter endpoints. See Control Endpoints from the Detections pane for details.

images/image109.png

Use lists to customize the asset inventory

The Asset Inventory automatically detects a wide range of network activity that you can organize into logical categories. For example, you may discover via the Asset Inventory that your network is working with a variety of authorized and unauthorized processes. If this is the case, you can create Lists of authorized and unauthorized processes under the Process Running property folder or lists of Switch IP addresses per VLAN under the Switch folder.

Working with inventory lists enables more customized, smoother tracking of network activity.

You can use lists when working with policies. For example, create a policy that tracks and stops machines running unauthorized processes. See Defining and Managing Lists for details.

Work with eyeSight segments

Segments are named groups of IP addresses. Use segments to represent your network in the Console in a way that reflects your organizational structure.

Note: Users with an eyeSegment license can access Segmentation (eyeSegment application)  from the toolbar.
Note: From eyeSight v8.4, the Forescout Admin (REST) API provides you with automatic configuration capabilities for managing deployments on the eyeSight, where network entities, such as the segment tree and default groups ranges, can change on a daily basis. The Admin API allows you to integrate third-party network management IPAM (IP Address Management) tools, such as Infoblox and BlueCat, and ensures that segments defined on the eyeSight are synchronized with their latest IPAM database definitions. For more information, see Work with the Forescout Admin API in the Admin API Plugin Configuration Guide.

Segments let you organize endpoints into logical categories within Forescout. For example, you can define segments for Sales or Finance departments in your organization. Sub-segments can also be created: Create a Sales category and, under that, Local Sales and International Sales categories.

The segments you create appear in the Filters pane of the Console.

images/image111.png

After you define segments, you can use them to:

  • Filter the Detections pane. For example, display endpoints in the Sales department that match a specific policy.
  • Specify IP addresses for Forescout features. For example, use predefined segments to specify the scope of a policy, antivirus tool, or Virtual Firewall.
  • Work with the site Map. For example, create a location called NYC-HQ, New York and then assign the respective segments in the NYC-HQ office network to this location. See Set Up the Map - Create Site Locations for details.
  • Create reports based on segments, for example, Compliance trends per segment. See Generating Reports and Logs for details.

When you work with segments:

  • Modifying an existing segment changes the IP addresses that are referenced by the segment wherever it is used in eyeSight. For example, the scope of policies may change, or the Appliance that handles certain IP addresses may change.
  • You can use the Audit Trails reports to search for information about users who have modified segment definitions.
  • One set of segments is shared among all eyeSight.

Note: Users with an eyeSegment license can access Segmentation (eyeSegment application)  from the toolbar.

Remove segments from the tree

Removing segments from the Segment tree only deletes the segment name. If you have already assigned IP addresses to this segment, Forescout products still handle endpoints with those IP addresses.

However, references to the segment in policies and other areas of the Console indicate that no segment name is assigned.

images/image117.png

Conversely, if you remove IP assignments from the Ranges area, those IP addresses are no longer included in the segment.

images/image118.png

If only empty segments are assigned to a failover cluster, and you want to remove one of the segments, you must first remove it from all failover cluster folder assignments before you remove it from the Segment tree. See Working with Appliance Folders and the Forescout eyeSight Resiliency and Recovery Solutions User Guide for more information.

File formats for importing and exporting the segment tree

You can export or import the entire segment tree or a specific segment. You may want to export segments if you are doing extensive editing and additions and want to use an external tool. You can also use the exported file as a template that reflects the file format required for importing.

Segment data (segment names and address ranges) is imported or exported in two file formats: XML or CSV.

A typical CSV file has the following format:

Segment ID,Parent Segment ID,Current Segment ID,Segment 
Name,From,To,Segment Description0,-1,0,Segments,,,1,0,3921800411724927309,internal network,10.160.50.1,10.160.50.120,

After the header line, each segment is as a line of the file, with the following fields:

Segment ID
A numerical ID assigned to each segment. This value must be unique in the segment tree.
Parent Segment ID
The parent ID of each segment. Each segment must have a parent. The parent ID for the root segment is -1.
Segment Name
A name assigned to the segment. This name is displayed in the Filters pane and Information table.
From/To
IP address range of the segment. If there are several ranges within the segment, those ranges must have the same segment ID, parent ID, and name.

Common spreadsheet applications can be used to edit CSV files, as shown below.

images/image119.png

The same simple tree shown in CSV format is shown below in XML format.

<?xml version="1.0" encoding="UTF-8" standalone="no"?>GROUP DESCRIPTION="" NAME="Segments" SEGMENT_ID="0" 
UPGRADE_PERFORMED="true">    <GROUP DESCRIPTION="" NAME="internal network" 
SEGMENT_ID="3921800411724927309" UPGRADE_PERFORMED="true">        <RANGES RANGE="10.160.50.1-10.160.50.120"/>    </GROUP></GROUP>

The <GROUP> element is used to define segments, and can be nested to show tree structure. The segment name, description, and unique numerical ID are represented by attributes of the <GROUP> element.

The <RANGE> element is used to define IP addresses in the segment.