Fortinet black logo

Administration Guide

Introduction

Introduction

The FortiEDR Dashboard provides a visual overview of the FortiEDR protection of your organization. It provides an at-a-glance view of the current security events and system health. The Dashboard is automatically displayed after installation or when you click the DASHBOARD tab.

Note

The system time is displayed in all pages at the bottom right of the status bar. It represents the local FortiEDR server time. For example, if the FortiEDR server is located in London, and you log in from Los Angeles, USA, then the time shown is the current time in London, and not the current time in Los Angeles.

The Dashboard enables you to display two different slices or views of the data collected by FortiEDR:

  • Device View (): This view presents information by device, and represents all the security events detected on a given device.
  • Process View (): This view presents information by process, and represents all the security events detected for a given process.

Click the applicable view button at the top left of the window to display that view in the DASHBOARD tab.

The information presented in the Dashboard represents an aggregation of events. For more details, you may refer to the Event Aggregation. FortiEDR aggregates security events in both the Device view and the Process view in the Dashboard.

Use the Logged-in User dropdown list at the top-right of the window to access the following options:

  • Getting Started: Opens the FortiEDR Getting Started window where you can watch a series of getting started videos for orientation within the FortiEDR environment. Use the videos to learn more about how to deploy and use FortiEDR.

    You can change the window location over the screen, resize or minimize the window using the provided buttons at the bottom right. Progress of the current video is not kept after you switch to another one. You have to start over with the current video after switching back.

    The following videos are currently available but the list is subject to change without notice:

    Section

    Videos

    Deployment PerquisitesResource for IT Guidelines
    Support for Mac, Windows, Linux OS
    Legacy End of Life Operating Systems
    SCCM Whitelisting
    AV Whitelisting
    Create Users and Notifications

    Central Manager: Create Secondary Admin
    Enable 2FA
    Create Email Distribution List

    Deploy FortiEDR Collectors

    Request FortiEDR Collector
    Create Server Collector Group
    Install Collector Win64
    Win Collector Command Line Install
    Linux Collector Command Line Install
    Win Collector Troubleshooting

    Post-Deployment

    BPS Lite Checklist
    Collector Troubleshooting
  • Help: Opens the FortiEDR documentation portal where you can access all FortiEDR documents, such as the FortiEDR Administration Guide and Release Notes.
  • Privacy Policy: Downloads the FortiEDR privacy policy.
  • Logout: Exits the FortiEDR application.

Introduction

The FortiEDR Dashboard provides a visual overview of the FortiEDR protection of your organization. It provides an at-a-glance view of the current security events and system health. The Dashboard is automatically displayed after installation or when you click the DASHBOARD tab.

Note

The system time is displayed in all pages at the bottom right of the status bar. It represents the local FortiEDR server time. For example, if the FortiEDR server is located in London, and you log in from Los Angeles, USA, then the time shown is the current time in London, and not the current time in Los Angeles.

The Dashboard enables you to display two different slices or views of the data collected by FortiEDR:

  • Device View (): This view presents information by device, and represents all the security events detected on a given device.
  • Process View (): This view presents information by process, and represents all the security events detected for a given process.

Click the applicable view button at the top left of the window to display that view in the DASHBOARD tab.

The information presented in the Dashboard represents an aggregation of events. For more details, you may refer to the Event Aggregation. FortiEDR aggregates security events in both the Device view and the Process view in the Dashboard.

Use the Logged-in User dropdown list at the top-right of the window to access the following options:

  • Getting Started: Opens the FortiEDR Getting Started window where you can watch a series of getting started videos for orientation within the FortiEDR environment. Use the videos to learn more about how to deploy and use FortiEDR.

    You can change the window location over the screen, resize or minimize the window using the provided buttons at the bottom right. Progress of the current video is not kept after you switch to another one. You have to start over with the current video after switching back.

    The following videos are currently available but the list is subject to change without notice:

    Section

    Videos

    Deployment PerquisitesResource for IT Guidelines
    Support for Mac, Windows, Linux OS
    Legacy End of Life Operating Systems
    SCCM Whitelisting
    AV Whitelisting
    Create Users and Notifications

    Central Manager: Create Secondary Admin
    Enable 2FA
    Create Email Distribution List

    Deploy FortiEDR Collectors

    Request FortiEDR Collector
    Create Server Collector Group
    Install Collector Win64
    Win Collector Command Line Install
    Linux Collector Command Line Install
    Win Collector Troubleshooting

    Post-Deployment

    BPS Lite Checklist
    Collector Troubleshooting
  • Help: Opens the FortiEDR documentation portal where you can access all FortiEDR documents, such as the FortiEDR Administration Guide and Release Notes.
  • Privacy Policy: Downloads the FortiEDR privacy policy.
  • Logout: Exits the FortiEDR application.