Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Detections

Detections

A detection is a suspicious activity occurring on a managed node that:

  • breaches corporate security policies as defined by a FortiDLP policy (policy detection)
  • violates a built-in FortiDLP Agent anti-tamper policy (embedded policy detection), or
  • indicates node inactivity (Agent offline detection).

You can view detections from the:

Investigate module: Detection event stream

When a detection is displayed in the FortiDLP Console, it is accompanied by a risk score and a severity to ease security threat prioritization. The risk score and severity correspond to the related detection rule based on the following scale.

Severity scale

For information on configuring detection rules, see Configuring the Agent offline warning and Configuring policy templates.

Detections

Detections

A detection is a suspicious activity occurring on a managed node that:

  • breaches corporate security policies as defined by a FortiDLP policy (policy detection)
  • violates a built-in FortiDLP Agent anti-tamper policy (embedded policy detection), or
  • indicates node inactivity (Agent offline detection).

You can view detections from the:

Investigate module: Detection event stream

When a detection is displayed in the FortiDLP Console, it is accompanied by a risk score and a severity to ease security threat prioritization. The risk score and severity correspond to the related detection rule based on the following scale.

Severity scale

For information on configuring detection rules, see Configuring the Agent offline warning and Configuring policy templates.