Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Adding events and detections to cases

Adding events and detections to cases

You can add events and detections to a case from various parts of the FortiDLP Console.

Follow these instructions to add an event or a detection to a case from either the Investigate or Incidents module.

How to add an event/detection to a case from the Investigate module
  1. In the FortiDLP Console, click .
  2. Do one of the following:
    • To add an event/detection from the Event streams tab:
      1. Click an event stream.
      2. Filter for the relevant event/detection. For details, see Viewing event streams.
      3. In the Events section, select the table row of the event/detection you want to add.
    • To add an event/detection from the Activity feed tab:
      1. Select the Activity feed tab.
      2. Filter for the relevant event/detection. For details, see Viewing the Activity feed.
      3. Select the table row of the event/detection you want to add.
  3. At the top of the Event/Detection details panel, click Add to case.
  4. Do one of the following:
    • To add the event/detection to a recent case, in the Recent tab, locate the case in the list and click Add.
    • To add the event/detection to an older case:
      1. Select the Open cases tab.
      2. Locate the case in the list and click Add.
How to add a detection to a case from the Incidents module
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant incident. For details, see Viewing incidents.
  3. In the Incidents table, select the row of incident comprising the relevant detection.
  4. In the table at the bottom of the page, select the row of the detection you want to add.

  5. At the top of the Detection details panel, click Add to case.
  6. Do one of the following:
    • To add the detection to a recent case, in the Recent tab, locate the case in the list and click Add.
    • To add the detection to an older case:
      1. Select the Open cases tab.
      2. Locate the case in the list and click Add.

Adding events and detections to cases

Adding events and detections to cases

You can add events and detections to a case from various parts of the FortiDLP Console.

Follow these instructions to add an event or a detection to a case from either the Investigate or Incidents module.

How to add an event/detection to a case from the Investigate module
  1. In the FortiDLP Console, click .
  2. Do one of the following:
    • To add an event/detection from the Event streams tab:
      1. Click an event stream.
      2. Filter for the relevant event/detection. For details, see Viewing event streams.
      3. In the Events section, select the table row of the event/detection you want to add.
    • To add an event/detection from the Activity feed tab:
      1. Select the Activity feed tab.
      2. Filter for the relevant event/detection. For details, see Viewing the Activity feed.
      3. Select the table row of the event/detection you want to add.
  3. At the top of the Event/Detection details panel, click Add to case.
  4. Do one of the following:
    • To add the event/detection to a recent case, in the Recent tab, locate the case in the list and click Add.
    • To add the event/detection to an older case:
      1. Select the Open cases tab.
      2. Locate the case in the list and click Add.
How to add a detection to a case from the Incidents module
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant incident. For details, see Viewing incidents.
  3. In the Incidents table, select the row of incident comprising the relevant detection.
  4. In the table at the bottom of the page, select the row of the detection you want to add.

  5. At the top of the Detection details panel, click Add to case.
  6. Do one of the following:
    • To add the detection to a recent case, in the Recent tab, locate the case in the list and click Add.
    • To add the detection to an older case:
      1. Select the Open cases tab.
      2. Locate the case in the list and click Add.