Fortinet white logo
Fortinet white logo

FortiDLP Console User Guide

Running out-of-box Investigate searches

Running out-of-box Investigate searches

The Investigate module's search menu provides a list of preconfigured out-of-box (OOB) searches. In just a click, you can execute an OOB search, filtering users and nodes by specific activities or characteristics.

Example

For example, the Browser downloads OOB search helps identify users who are downloading files via a web browser.

How to run an OOB Investigate search
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. At the top of the page, click the search bar.
  3. Click Out-of-box searches.
  4. Click the search you want to execute.

    The FortiDLP Console highlights the event stream panels where the OOB search filters have been applied.
  5. Tooltip

    You can view OOB search descriptions within tooltips by hovering your cursor over the search names.

To clear an OOB search, hover over the search name on the menu bar and then click X.

Running out-of-box Investigate searches

Running out-of-box Investigate searches

The Investigate module's search menu provides a list of preconfigured out-of-box (OOB) searches. In just a click, you can execute an OOB search, filtering users and nodes by specific activities or characteristics.

Example

For example, the Browser downloads OOB search helps identify users who are downloading files via a web browser.

How to run an OOB Investigate search
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. At the top of the page, click the search bar.
  3. Click Out-of-box searches.
  4. Click the search you want to execute.

    The FortiDLP Console highlights the event stream panels where the OOB search filters have been applied.
  5. Tooltip

    You can view OOB search descriptions within tooltips by hovering your cursor over the search names.

To clear an OOB search, hover over the search name on the menu bar and then click X.