Viewing detection reports
To view a detection report, follow these steps.
How to view a detection report
- In the FortiDLP Console, on the left-hand sidebar, click .
- Do one of the following:
- To view a report of all detections across the organization, click All detections.
- To view a report of detections for entities that are assigned a flagged label, click Flagged entities reports and then click the relevant label name.
- To view a custom report of detections, click Custom reports and then click the relevant report name.
- To view a report of detections for a specific policy group, click Policy group reports and then click the relevant policy group name.
- Optionally, do the following:
- To modify the time frame, do one of the following:
- To filter using a time preset:
- On the right side of the menu bar, click.
- Click one of the following options:
- Last 60 min
- Today
- Last 24 hours
- Last 7 days
- Last 30 days.
- To filter using custom time frame:
- On the right side of the menu bar, click.
- In the From field, type or select the start date and time.
- In the To fields, type or select the end date and time.
- Click Apply.
- To filter using a time preset:
- To filter detections by type, on the top-right side of the page, clickand then turn the relevant toggles on/off. You can show/hide policy detections, behavioral analytics detections (machine learning and Agent offline), and embedded policy detections.
- To modify the aggregations, select different properties from the menus. The menu options displayed depend on the properties selected in the other two menus.
- To increase the aggregation values, select
10
,20
, or100
(5
is selected by default). - To modify the table columns, click Columns and then select/deselect the relevant checkboxes.
- To increase/decrease the number of detections shown on the page, in the Items/page menu, select
10
,25
, or50
. - To filter by a property value, hover over the value and click to execute an equals search or click to execute a does not equal search.
- To inspect events related to a property value on the Investigate module, hover over the value, click > Add filter and go to Investigate.
- To inspect events occurring within a minute of the detection in the Activity feed, on the row of the relevant detection, click .
- To view or edit a policy configuration, hover over the policy name and click .
- To export the report:
- On the top-right side of the page, click> Export.
- In the Format section, select either the CSV or XLSX radio button.
- In the Fields section, select the checkboxes for the fields you want shown in the report.
- Click Export.
- On the top-right side of the page, click> Export.
For example, hovering over a policy name and clicking removes data for that particular policy while hovering over a policy name and clicking removes data for all other policies.
- To modify the time frame, do one of the following: