Threat Hunting Settings
Note: Threat Hunting Settings is a license-dependent add-on. You may contact Fortinet Support for more information.
Threat Hunting Settings control the type of activity data that is collected for the Threat Hunting feature (which is described in Threat Hunting). Activity data that is collected is stored on the Repository server.
To access Threat Hunting settings, select SECURITY SETTINGS > Threat Hunting Settings. The following page displays:
The left side of the Threat Hunting Settings page shows a list of Profiles. A Profile defines the activity event categories and actions to be collected. FortiEDR comes with several predefined default Profiles, which cannot be modified.
In addition to the pre-defined Profiles, you can define your own custom Profiles by cloning an existing Profile.
The pane on the right side of the page lists all activity event categories and their associated actions. These categories are the same as those described on Threat Hunting
Selecting a Profile on the left displays the categories and actions defined for that Profile in the right pane.
Check the checkboxes of the actions for which FortiEDR will collect activity data.