Requesting scoped investigations
As an investigator, you can submit scoped investigation requests from the Incidents, Users, or Nodes modules, as described in the following instructions.
After you submit a request, the
icon on the top menu bar of the FortiDLP Console will keep you informed.
- If a request is pending, the bell will display a blue circle.
- If a request is approved/activated, the bell will display a green circle.
- If a request is denied/revoked, the bell will display a red circle.
|
|
Where you have requests with different statuses, one circle will display, with green taking precedence, followed by red;
|
To see your requests, just click the
icon and select the My investigations menu option to go to the Scoped investigations tab. Alternatively, you can view requests in the Scoped investigations tab via Admin settings.
How to request a scoped investigation
- In the FortiDLP Console, do one of the following:
- To request an investigation from the Incidents module:
- On the left-hand sidebar, click
.
- At the end of the incident's table row, click
> Request investigation.


You can also click an incident's table row to request the investigation from the Incident details page.

- On the left-hand sidebar, click
- To request an investigation from the Users module:
- On the left-hand sidebar, click
.
- At the end of the user's table row, click
> Request investigation.

- On the left-hand sidebar, click
- To request an investigation from the Nodes module:
- On the left-hand sidebar, click
.
- Filter for the relevant node. For guidance on this, see Nodes.
- In the Table tab, at the end of the node's table row, click
> Request investigation.


You can also click a node's table row to request the investigation from Node profile page.
- On the left-hand sidebar, click
- To request an investigation from the Incidents module:
- In the Request investigation dialog box, do the following:
- In the Investigation name field, type a name to identify the investigation. (If you performed step 1 from the Incidents module, the incident's description will be prepopulated, but you can edit this.)
- In the Scoped users list, select the users to investigate, a maximum of 20. (If you performed step 1 from the Incidents module or the Users module, a maximum of 10 corresponding user(s) will be preselected.)
- In the Scoped nodes list, select the nodes to investigate, a maximum of 20. (If you performed step 1 from the Nodes module, the node's hostname will be preselected.)
- In the Scoped event streams list, select the event streams to investigate. By default, all event streams will be preselected.
- Set the time range of the events to investigate:
- To limit the time range, keep the Limit time range toggle on and either select a time preset or enter a custom time range.
- To place no limit on the time range, turn the Limit time range toggle off.
- In the Investigation reason field, type the investigation reason.
- Click Send request.