Viewing detection reports
To view a detection report, follow these steps.
How to view a detection report
- In the FortiDLP Console, on the left-hand sidebar, click
.
- Do one of the following:
- To view a custom report of detections, remain in the Custom reports tab.
- To view a report of detections for a specific policy group, select the Policy groups tab.
- To view a report of detections for entities that are assigned a flagged label, select the Flagged entities tab.
- Optionally, do the following:
- To modify the time frame of all reports, do one of the following:
- To filter using a time preset:
- On the top right of the page, click
.
- Click one of the following options:
- Last 60 min
- Today
- Last 24 hours
- Last 7 days
- Last 30 days.

- On the top right of the page, click
- To filter using a custom time frame:
- On the top right of the page, click
.
- In the From field, type or select the start date and time.
- In the To fields, type or select the end date and time.
- Click Apply.
- On the top right of the page, click
- To filter using a time frame of a bar in a bar graph:
- On the bar graph in a report, click a bar.
- In the context box, click Set time range.

- To filter using a time preset:
- To view further information about a report:
- To view a breakdown of the number of detections by severity, on a bar graph in a report, click a bar that contains multiple colors.
- To pivot to the Investigate module to view detailed detection data, on the report widget, click
.

You will be brought to the Detection event stream, which will be filtered by the policy group, flagged entity, or custom query that forms the report. For guidance on viewing and exporting event streams, see Viewing event streams and Exporting event streams.
- To modify the time frame of all reports, do one of the following: