Activity feed
The Activity feed displays, by default, a list of events in chronological order, so you can easily see the latest activity occurring in your organization.
You can click an event to show all of its details, and filter the list by defining a time range, performing search queries, and selecting one or more event streams. With the interactive table, you can pivot to related information and create search queries to dig further into information of interest.
Above the events table, the total number of events, associated users, and associated nodes is shown for each selected event stream.
Pinned event fields
In the table, you can expand an event to view all of its details and then pin important fields to a column to access the information most useful for your investigations. By default, the Actions field is automatically pinned for detection events.
Pinning fields
Pinned fields column
Event streams panel
The event streams panel lets you filter which streams are visible in the events table. You can manually select one or more streams or turn on a toggle to enable the automatic selection of streams that match a query entered into the search bar at the top of the page.
Aggregations panel
In the Aggregations panel, you can view high-level statistics for any event stream, so you can add context related to your current investigation or begin a new one side by side.
The following table describes the event types the Activity feed captures. For details regarding OS and Agent compatibilities and requirements, refer to the FortiDLP Agent Deployment Guide.
Event type | Description | ||
---|---|---|---|
|
Events related to manual (operator-initiated) and automatic (policy-initiated) actions. You can view details including the:
For comprehensive information about actions, also see Actions. |
||
Application |
Events related to application use. You can view details including the:
|
||
Browser |
Events related to browser use, such as when a user visits a URL or uploads or downloads a file. You can view details including the:
|
||
Detection |
Events related to detections. You can view details including the:
For comprehensive information about actions, also see Detections. |
||
Events related to outbound email activity. You can view details including the:
|
|||
File access |
Events related to file access, such as when a file is opened, modified, closed, executed, deleted, or renamed. You can view details including the:
|
||
Google Drive |
Events collected from Google Drive. You can view details including the:
|
||
Login |
Events related to login activity. You can view details including the:
|
||
Network connection |
Events related to network connections. You can view details including the:
|
||
Events related to print jobs. For Windows machines, print jobs sent to local, network, and virtual printers are monitored. For macOS and Linux machines, prints jobs sent to local and network printers are monitored. You can view details including the:
|
|||
Process start |
Events related to process starts. You can view details including the:
|
||
SharePoint & OneDrive |
Events collected from Microsoft SharePoint and OneDrive. You can view details including the:
|
||
USB device |
Events related to USB composite and storage device use. You can view details including the:
|
||
Wi-Fi |
Events related to Wi-Fi network connections. You can view details including the:
|