Fortinet black logo

Investigations

Investigations

Investigations collate alert information in a single location. To prepare reports, you can use the collated information. For example, you can create a report to submit to HR or a data regulator.

Creating investigations

To create an investigation, click Start Investigation in the details page for any alert. You can also add alerts to existing investigations from here. You can create investigations based on policy alerts, AI alerts, or a combination of both. You can also add notes to provide context around alerts.

Using investigations

Investigations have the following options:

  • Owners: Investigations have an owner. If you want to transfer the ownership to someone else, you can change the owner by editing the investigation.
  • Note: You can add notes to an investigation to add context and comments to alerts that have been recorded.
  • Update Status: You can update the status of an investigation to Reported, No action, or Open.

Exporting investigations

To export investigations as CSV files, first navigate to the Investigation Details page of the desired investigation. To do so, pick a type of investigation (Open, Reported, No Action, or Closed) from the Investigations drop-down menu and then select the row of the desired investigation from the table of investigations.

The following image shows an example of a selected row from the table of investigations on the Investigations page, outlined in red:

You can then export the investigation as a CSV file by clicking the Export to CSV button below the Policy Alerts or AI Aerts search bar on the Investigation Details page.

The following image shows the location of the Export to CSV button, outlined in red:

To export Investigation notes, use the Export Notes as CSV button under the Export Investigation Notes heading on the righthand side of the UI.

The following image shows the location of the Export Notes as CSV button, outlined in red:

Investigations

Investigations collate alert information in a single location. To prepare reports, you can use the collated information. For example, you can create a report to submit to HR or a data regulator.

Creating investigations

To create an investigation, click Start Investigation in the details page for any alert. You can also add alerts to existing investigations from here. You can create investigations based on policy alerts, AI alerts, or a combination of both. You can also add notes to provide context around alerts.

Using investigations

Investigations have the following options:

  • Owners: Investigations have an owner. If you want to transfer the ownership to someone else, you can change the owner by editing the investigation.
  • Note: You can add notes to an investigation to add context and comments to alerts that have been recorded.
  • Update Status: You can update the status of an investigation to Reported, No action, or Open.

Exporting investigations

To export investigations as CSV files, first navigate to the Investigation Details page of the desired investigation. To do so, pick a type of investigation (Open, Reported, No Action, or Closed) from the Investigations drop-down menu and then select the row of the desired investigation from the table of investigations.

The following image shows an example of a selected row from the table of investigations on the Investigations page, outlined in red:

You can then export the investigation as a CSV file by clicking the Export to CSV button below the Policy Alerts or AI Aerts search bar on the Investigation Details page.

The following image shows the location of the Export to CSV button, outlined in red:

To export Investigation notes, use the Export Notes as CSV button under the Export Investigation Notes heading on the righthand side of the UI.

The following image shows the location of the Export Notes as CSV button, outlined in red: