Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Searches

Searches

Note

Operators who have pseudonymized access to the FortiDLP Console will be restricted from performing searches using identifying properties and viewing watchlists and saved searches containing identifying properties. For more information about pseudonymization, refer to the FortiDLP Administration Guide.

The Investigate module’s guided search functionality makes finding events a fast and efficient process. As you start typing into the search bar, the engine will immediately begin matching event data consisting of entities, properties, and aliases. Additionally, by clicking the search bar, you can view all out-of-box (OOB) searches and saved searches.

When performing a search, keep the following in mind:

  • A property is a search term that applies to a single event stream. Properties are listed below the relevant event stream heading in the search menu.
  • Example

    For example, the event_type property that falls under Browser properties allows you to filter by download, upload, and navigation events.

  • An alias is a search term that applies to multiple event streams. Aliases are listed below the Aliases heading in the search menu.
    Example

    For example, instead of just filtering the File access event stream by the file_name property, you could use the file_name alias to search across the Browser, Detection, Email, File access, Google Drive, Print , and SharePoint & OneDrive event streams.

Hints

As you type your query into the search bar, hints will be responsively suggested to you, helping you to create both simple and complex queries. Suggestions include valid operators, property/alias values, and formatting.

Saved searches

You can save your search queries so that you can easily conduct the same search in just a click, saving you even more time.

For more information, see Saving Investigate searches.

OOB searches

FortiDLP supplies preconfigured OOB searches that are helpful for finding events that are commonly associated with suspicious activity, such as Show outbound data transfers greater than 1GB.

For more information, see Running out-of-box Investigate searches.

Searches

Searches

Note

Operators who have pseudonymized access to the FortiDLP Console will be restricted from performing searches using identifying properties and viewing watchlists and saved searches containing identifying properties. For more information about pseudonymization, refer to the FortiDLP Administration Guide.

The Investigate module’s guided search functionality makes finding events a fast and efficient process. As you start typing into the search bar, the engine will immediately begin matching event data consisting of entities, properties, and aliases. Additionally, by clicking the search bar, you can view all out-of-box (OOB) searches and saved searches.

When performing a search, keep the following in mind:

  • A property is a search term that applies to a single event stream. Properties are listed below the relevant event stream heading in the search menu.
  • Example

    For example, the event_type property that falls under Browser properties allows you to filter by download, upload, and navigation events.

  • An alias is a search term that applies to multiple event streams. Aliases are listed below the Aliases heading in the search menu.
    Example

    For example, instead of just filtering the File access event stream by the file_name property, you could use the file_name alias to search across the Browser, Detection, Email, File access, Google Drive, Print , and SharePoint & OneDrive event streams.

Hints

As you type your query into the search bar, hints will be responsively suggested to you, helping you to create both simple and complex queries. Suggestions include valid operators, property/alias values, and formatting.

Saved searches

You can save your search queries so that you can easily conduct the same search in just a click, saving you even more time.

For more information, see Saving Investigate searches.

OOB searches

FortiDLP supplies preconfigured OOB searches that are helpful for finding events that are commonly associated with suspicious activity, such as Show outbound data transfers greater than 1GB.

For more information, see Running out-of-box Investigate searches.