Viewing event streams
Refer to these instructions to view event streams in either the Aggregations tab or the Events tab.
How to view Event streams in the Aggregations tab
- In the FortiDLP Console, on the left-hand sidebar, click .
- Remain in the Event streams tab.
By default, all events for the current day are aggregated. - Optionally, to filter events by using the search bar and/or a time range, see Performing Investigate searches.
If the search query matches events from an event stream, the event stream panel will be highlighted in blue.
- Select an event stream panel.
The Aggregations tab will be preselected. - Optionally, do the following:
- To modify the information displayed in a widget, click a menu and select a new value. Top menu options show the most common values for a property and Bottom menu options show you the least common values.
- To filter the events by a specific value on the page or view more information about a value, click the value and then click the relevant context box button.
- Filters the current page for events with the same value.
- Filters the current page for events without the value.
- Filters by a value within the SaaS apps module's Inventory tab.
- Copies a value to your clipboard.
- Displays more information about a value.
- Displays a submenu containing the following options:
- Filters by a value within the Users module.
- Filters by a value within the Nodes module (if selected from a user's context box) or takes you to the Node profile page (if selected from a node's context box).
- To view an event more closely in the Event details panel, click the event’s table row.
The following list summarizes the buttons that display:
- To modify the information displayed in a widget, click a menu and select a new value. Top menu options show the most common values for a property and Bottom menu options show you the least common values.
How to view Event streams in the Events tab
- In the FortiDLP Console, on the left-hand sidebar, click .
- Remain in the Event streams tab.
By default, all events for the current day are aggregated. - Optionally, to filter events by using the search bar and/or a time range, see Performing Investigate searches.
If the search query matches events from an event stream, the event stream panel will be highlighted in blue.
- Select an event stream panel.
The Aggregations tab will be preselected. - Select the Events tab.
- Optionally, do the following:
- To modify the table columns:
- Click Columns and select/deselect the relevant checkboxes.
- Change the Items/page default. You can show 50, 100, or 500 events on the page.
- To filter the events by a specific value on the page or view more information about a value, click the value and then click the relevant context box button.
- Filters the current page for events with the same value.
- Filters the current page for events without the value.
- Filters by a value within the SaaS apps module's Inventory tab.
- Copies a value to your clipboard.
- Displays more information about a value.
- Displays a submenu containing the following options:
- Filters by a value within the Users module.
- Filters by a value within the Nodes module (if selected from a user's context box) or takes you to the Node profile page (if selected from a node's context box).
- To filter the page for events occurring before, after, or around the same time as an event in the table, click the timestamp and set your preferred time range.
- To view an event more closely in the Event details panel, click the event’s table row.
The following list summarizes the buttons that display:
For example, selecting 10 minutes and the Around menu option would filter for events occurring during the 10 minutes before the timestamp and the 10 minutes after the timestamp.
- To modify the table columns: