Event streams
The Event streams tab categorizes events, enabling you to conduct focused searches and analyses centered around events that have the same root cause.
When you select an event stream, you are brought to a page that contains the events for the category. You can either view key event data within the Aggregations subtab, or access all of the events in a table within the Events subtab.
Aggregations
In the Aggregations subtab, you can view high-level statistics for event data and use key information in search queries. The widgets are customizable via menus that let you select the information you want to display.
Events
In the Events subtab, you can view events in more detail within an interactive table. If you click an event value, a context menu will display, allowing you to add it to a search query or to pivot to related information.
The following table describes the event types the Event streams tab captures. For details regarding OS and Agent compatibilities and requirements, refer to the FortiDLP Agent Deployment Guide.
Event type | Description | ||
---|---|---|---|
|
Events related to manual (operator-initiated) and automatic (policy-initiated) actions. You can view details including the:
For comprehensive information about actions, also see Actions. |
||
Application |
Events related to application use. You can view details including the:
|
||
Browser |
Events related to browser use, such as when a user visits a URL or uploads or downloads a file. You can view details including the:
|
||
Detection |
Events related to detections. You can view details including the:
For comprehensive information about actions, also see Detections. |
||
Events related to outbound email activity. You can view details including the:
|
|||
File access |
Events related to file access, such as when a file is opened, modified, closed, executed, deleted, or renamed. You can view details including the:
|
||
Google Drive |
Events collected from Google Drive. You can view details including the:
|
||
Login |
Events related to login activity. You can view details including the:
|
||
Network connection |
Events related to network connections. You can view details including the:
|
||
Events related to print jobs. For Windows machines, print jobs sent to local, network, and virtual printers are monitored. For macOS and Linux machines, prints jobs sent to local and network printers are monitored. You can view details including the:
|
|||
Process start |
Events related to process starts. You can view details including the:
|
||
SharePoint & OneDrive |
Events collected from Microsoft SharePoint and OneDrive. You can view details including the:
|
||
USB device |
Events related to USB composite and storage device use. You can view details including the:
|
||
Wi-Fi |
Events related to Wi-Fi network connections. You can view details including the:
|