Marking a security event as handled/unhandled
The following describes how to specify that you have handled a security event. When any FortiEDR Central Manager user marks a security event as Handled, all users see it as having been handled.
- Select the rule’s checkbox and then click the Handle event button or just click the flag icon of the security event row. The Event Handling window displays.
If an exception was already defined for this security event, then the words event includes exceptions are displayed at the top of the Event Handling window.
- In the Classification dropdown list, change the classification for the security event, if needed. For more details, see Manually changing the classification of a security event.
- In the comments box, use free text to describe how you handled the security event.
- Click the Save as Handled button. The flag icon next to the security event changes from dark gray to light gray to indicate to all users that it has been handled.
- (Optional) Check the Archive When Handled checkbox to archive the security event after handling it. When you select this option, the security event is marked both as handled and as archived.
- (Optional) Click the arrow to the left of Advanced to display the Mute events notification field. Select this checkbox if you want to mute the notifications for this security event. In addition, specify how long to mute the security event notifications. Notifications can be muted for any of the following periods: 1 Week, 1 Month, 1 Year, or Permanently. When checked, you will not receive notifications whenever this security event is triggered. When using this option, click the Save as Handled button, which indicates that the security event has been both handled and saved.
Security events with muted event notifications are indicated by the icon in the Event Viewer.