Adding events and detections to cases
You can add events and detections to a case from various parts of the FortiDLP Console.
Follow these instructions to add an event or a detection to a case from either the Investigate or Incidents module.
How to add an event/detection to a case from the Investigate module
- In the FortiDLP Console, click
.
- Do one of the following:
- To add an event/detection from the Event streams tab:
- Click an event stream.
- Filter for the relevant event/detection. For details, see Viewing event streams.
- In the Events section, select the table row of the event/detection you want to add.
- To add an event/detection from the Activity feed tab:
- Select the Activity feed tab.
- Filter for the relevant event/detection. For details, see Viewing the Activity feed.
- Select the table row of the event/detection you want to add.
- To add an event/detection from the Event streams tab:
- At the top of the Event/Detection details panel, click Add to case.

- Do one of the following:
- To add the event/detection to a recent case, in the Recent tab, locate the case in the list and click Add.
- To add the event/detection to an older case:
- Select the Open cases tab.
- Locate the case in the list and click Add.
How to add a detection to a case from the Incidents module
- In the FortiDLP Console, on the left-hand sidebar, click
.
- Filter for the relevant incident. For details, see Viewing incidents.
- In the Incidents table, select the row of incident comprising the relevant detection.
- In the table at the bottom of the page, select the row of the detection you want to add.

- At the top of the Detection details panel, click Add to case.
- Do one of the following:
- To add the detection to a recent case, in the Recent tab, locate the case in the list and click Add.
- To add the detection to an older case:
- Select the Open cases tab.
- Locate the case in the list and click Add.