Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Resolving incidents

Resolving incidents

When you finish investigating an incident, you can resolve it to hide it by default in the Incidents module. This is a permanent action, and detections will no longer be added to it.

The Incidents module lets you resolve incidents individually or in bulk, as follows.

How to resolve a single incident
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant incident by following the steps in Viewing incidents.
  3. Do one of the following:
    • To mark an incident as "Resolved" on the Incidents overview page:
      1. At the end of the incident's table row, click> Mark as Resolved.
    • To mark an incident as "Resolved" on the Incident details page:
      1. Select the incident's table row.
      2. On the top-right corner of the page, click Change status > Mark incident as Resolved.

  4. In the Resolve incident dialog box, do the following:
    1. Optionally, in the Reason field, type a reason for resolving the incident.
    2. Click Confirm.
How to resolve multiple incidents
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant incidents by following the steps in Viewing incidents.
  3. On the top-right corner of the page, click Change status > Mark [n] incidents as Resolved.
  4. In the Resolve [n] incidents dialog box, do the following:
    1. Optionally, in the Reason field, type a reason for resolving the incidents.
    2. Select the I confirm that I want to resolve [n] incidents checkbox.
    3. Click Confirm.

Resolving incidents

Resolving incidents

When you finish investigating an incident, you can resolve it to hide it by default in the Incidents module. This is a permanent action, and detections will no longer be added to it.

The Incidents module lets you resolve incidents individually or in bulk, as follows.

How to resolve a single incident
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant incident by following the steps in Viewing incidents.
  3. Do one of the following:
    • To mark an incident as "Resolved" on the Incidents overview page:
      1. At the end of the incident's table row, click> Mark as Resolved.
    • To mark an incident as "Resolved" on the Incident details page:
      1. Select the incident's table row.
      2. On the top-right corner of the page, click Change status > Mark incident as Resolved.

  4. In the Resolve incident dialog box, do the following:
    1. Optionally, in the Reason field, type a reason for resolving the incident.
    2. Click Confirm.
How to resolve multiple incidents
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Filter for the relevant incidents by following the steps in Viewing incidents.
  3. On the top-right corner of the page, click Change status > Mark [n] incidents as Resolved.
  4. In the Resolve [n] incidents dialog box, do the following:
    1. Optionally, in the Reason field, type a reason for resolving the incidents.
    2. Select the I confirm that I want to resolve [n] incidents checkbox.
    3. Click Confirm.