Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Cases

Cases

Designed to simplify threat hunting and forensic analysis, cases enable to you to investigate potential risks across your network.

In the FortiDLP Console, a case represents a group of suspicious events and detections. By building a case, you can proactively flag events and detections requiring investigation and then collaborate with other operators for more informed decision-making and rapid response.

The Cases module displays three categories of cases:

  • The Open cases panel shows cases being actively investigated by operators within your organization.
  • The Closed cases panel shows cases that were previously investigated by operators within your organization or Fortinet Cyber Analysts.
  • The By Fortinet Cyber Analysts panel shows cases being actively investigated by Fortinet Cyber Analysts.

By clicking a case, you can navigate to the corresponding Case details page, where you can view and manage the case.

To learn more, see:

Cases

Cases

Designed to simplify threat hunting and forensic analysis, cases enable to you to investigate potential risks across your network.

In the FortiDLP Console, a case represents a group of suspicious events and detections. By building a case, you can proactively flag events and detections requiring investigation and then collaborate with other operators for more informed decision-making and rapid response.

The Cases module displays three categories of cases:

  • The Open cases panel shows cases being actively investigated by operators within your organization.
  • The Closed cases panel shows cases that were previously investigated by operators within your organization or Fortinet Cyber Analysts.
  • The By Fortinet Cyber Analysts panel shows cases being actively investigated by Fortinet Cyber Analysts.

By clicking a case, you can navigate to the corresponding Case details page, where you can view and manage the case.

To learn more, see: