Searches
Operators who have pseudonymized access to the FortiDLP Console will be restricted from performing searches using identifying properties and viewing watchlists and saved searches containing identifying properties. For more information about pseudonymization, refer to the FortiDLP Administration Guide. |
The Investigate module’s guided search functionality makes finding events a fast and efficient process. As you start typing into the search bar, the engine will immediately begin matching event data consisting of entities, properties, and aliases. Additionally, by clicking the search bar, you can view all out-of-box (OOB) searches and saved searches.
When performing a search, keep the following in mind:
- A property is a search term that applies to a single event stream. Properties are listed below the relevant event stream heading in the search menu.
- An alias is a search term that applies to multiple event streams. Aliases are listed below the Aliases heading in the search menu.
For example, instead of just filtering the File access event stream by the
file_name
property, you could use thefile_name
alias to search across the Browser, Detection, Email, File access, Google Drive, Print , and SharePoint & OneDrive event streams.
For example, the
|
Hints
As you type your query into the search bar, hints will be responsively suggested to you, helping you to create both simple and complex queries. Suggestions include valid operators, property/alias values, and formatting.
Saved searches
You can save your search queries so that you can easily conduct the same search in just a click, saving you even more time.
For more information, see Saving Investigate searches.
OOB searches
FortiDLP supplies preconfigured OOB searches that are helpful for finding events that are commonly associated with suspicious activity, such as Show outbound data transfers greater than 1GB.
For more information, see Running out-of-box Investigate searches.