Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Viewing detection reports

Viewing detection reports

To view a detection report, follow these steps.

How to view a detection report
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Do one of the following:
    • To view a report of all detections across the organization, click All detections.
    • To view a report of detections for entities that are assigned a flagged label, click Flagged entities reports and then click the relevant label name.
    • To view a custom report of detections, click Custom reports and then click the relevant report name.
    • To view a report of detections for a specific policy group, click Policy group reports and then click the relevant policy group name.
  3. Optionally, do the following:
    • To modify the time frame, do one of the following:
      • To filter using a time preset:
        1. On the right side of the menu bar, click.
        2. Click one of the following options:
          • Last 60 min
          • Today
          • Last 24 hours
          • Last 7 days
          • Last 30 days.
      • To filter using custom time frame:
        1. On the right side of the menu bar, click.
        2. In the From field, type or select the start date and time.
        3. In the To fields, type or select the end date and time.
        4. Click Apply.
    • To filter detections by type, on the top-right side of the page, clickand then turn the relevant toggles on/off. You can show/hide policy detections, behavioral analytics detections (machine learning and Agent offline), and embedded policy detections.
    • To modify the aggregations, select different properties from the menus. The menu options displayed depend on the properties selected in the other two menus.
    • To increase the aggregation values, select 10, 20, or 100 (5 is selected by default).
    • To modify the table columns, click Columns and then select/deselect the relevant checkboxes.
    • To increase/decrease the number of detections shown on the page, in the Items/page menu, select 10, 25, or 50.
    • To filter by a property value, hover over the value and click to execute an equals search or click to execute a does not equal search.
    • Example

      For example, hovering over a policy name and clicking removes data for that particular policy while hovering over a policy name and clicking removes data for all other policies.

    • To inspect events related to a property value on the Investigate module, hover over the value, click > Add filter and go to Investigate.
    • To inspect events occurring within a minute of the detection in the Activity feed, on the row of the relevant detection, click .
    • To view or edit a policy configuration, hover over the policy name and click .
    • To export the report:
      1. On the top-right side of the page, click> Export.
      2. In the Format section, select either the CSV or XLSX radio button.
      3. In the Fields section, select the checkboxes for the fields you want shown in the report.
      4. Click Export.

Viewing detection reports

Viewing detection reports

To view a detection report, follow these steps.

How to view a detection report
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Do one of the following:
    • To view a report of all detections across the organization, click All detections.
    • To view a report of detections for entities that are assigned a flagged label, click Flagged entities reports and then click the relevant label name.
    • To view a custom report of detections, click Custom reports and then click the relevant report name.
    • To view a report of detections for a specific policy group, click Policy group reports and then click the relevant policy group name.
  3. Optionally, do the following:
    • To modify the time frame, do one of the following:
      • To filter using a time preset:
        1. On the right side of the menu bar, click.
        2. Click one of the following options:
          • Last 60 min
          • Today
          • Last 24 hours
          • Last 7 days
          • Last 30 days.
      • To filter using custom time frame:
        1. On the right side of the menu bar, click.
        2. In the From field, type or select the start date and time.
        3. In the To fields, type or select the end date and time.
        4. Click Apply.
    • To filter detections by type, on the top-right side of the page, clickand then turn the relevant toggles on/off. You can show/hide policy detections, behavioral analytics detections (machine learning and Agent offline), and embedded policy detections.
    • To modify the aggregations, select different properties from the menus. The menu options displayed depend on the properties selected in the other two menus.
    • To increase the aggregation values, select 10, 20, or 100 (5 is selected by default).
    • To modify the table columns, click Columns and then select/deselect the relevant checkboxes.
    • To increase/decrease the number of detections shown on the page, in the Items/page menu, select 10, 25, or 50.
    • To filter by a property value, hover over the value and click to execute an equals search or click to execute a does not equal search.
    • Example

      For example, hovering over a policy name and clicking removes data for that particular policy while hovering over a policy name and clicking removes data for all other policies.

    • To inspect events related to a property value on the Investigate module, hover over the value, click > Add filter and go to Investigate.
    • To inspect events occurring within a minute of the detection in the Activity feed, on the row of the relevant detection, click .
    • To view or edit a policy configuration, hover over the policy name and click .
    • To export the report:
      1. On the top-right side of the page, click> Export.
      2. In the Format section, select either the CSV or XLSX radio button.
      3. In the Fields section, select the checkboxes for the fields you want shown in the report.
      4. Click Export.