Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Viewing detection reports

Viewing detection reports

To view a detection report, follow these steps.

How to view a detection report
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Do one of the following:
    • To view a custom report of detections, remain in the Custom reports tab.
    • To view a report of detections for a specific policy group, select the Policy groups tab.
    • To view a report of detections for entities that are assigned a flagged label, select the Flagged entities tab.
  3. Optionally, do the following:
    • To modify the time frame of all reports, do one of the following:
      • To filter using a time preset:
        1. On the top right of the page, click.
        2. Click one of the following options:
          • Last 60 min
          • Today
          • Last 24 hours
          • Last 7 days
          • Last 30 days.
      • To filter using a custom time frame:
        1. On the top right of the page, click.
        2. In the From field, type or select the start date and time.
        3. In the To fields, type or select the end date and time.
        4. Click Apply.
      • To filter using a time frame of a bar in a bar graph:
        1. On the bar graph in a report, click a bar.
        2. In the context box, click Set time range.
    • To view further information about a report:
      • To view a breakdown of the number of detections by severity, on a bar graph in a report, click a bar that contains multiple colors.
      • To pivot to the Investigate module to view detailed detection data, on the report widget, click .
        NoteYou will be brought to the Detection event stream, which will be filtered by the policy group, flagged entity, or custom query that forms the report. For guidance on viewing and exporting event streams, see Viewing event streams and Exporting event streams.

Viewing detection reports

Viewing detection reports

To view a detection report, follow these steps.

How to view a detection report
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Do one of the following:
    • To view a custom report of detections, remain in the Custom reports tab.
    • To view a report of detections for a specific policy group, select the Policy groups tab.
    • To view a report of detections for entities that are assigned a flagged label, select the Flagged entities tab.
  3. Optionally, do the following:
    • To modify the time frame of all reports, do one of the following:
      • To filter using a time preset:
        1. On the top right of the page, click.
        2. Click one of the following options:
          • Last 60 min
          • Today
          • Last 24 hours
          • Last 7 days
          • Last 30 days.
      • To filter using a custom time frame:
        1. On the top right of the page, click.
        2. In the From field, type or select the start date and time.
        3. In the To fields, type or select the end date and time.
        4. Click Apply.
      • To filter using a time frame of a bar in a bar graph:
        1. On the bar graph in a report, click a bar.
        2. In the context box, click Set time range.
    • To view further information about a report:
      • To view a breakdown of the number of detections by severity, on a bar graph in a report, click a bar that contains multiple colors.
      • To pivot to the Investigate module to view detailed detection data, on the report widget, click .
        NoteYou will be brought to the Detection event stream, which will be filtered by the policy group, flagged entity, or custom query that forms the report. For guidance on viewing and exporting event streams, see Viewing event streams and Exporting event streams.