Fortinet white logo
Fortinet white logo

User Guide

Running a guided query of event records

Running a guided query of event records

To run a guided query of event records:
  1. Go to Investigations > Investigate and select an investigation from the list.

  2. Click View Results to view the investigation results.

  3. Right click on an entity to open the context menu and select Guided Queries.

    Playbooks

  4. Select a guided query from the list. If the event record has matching variables in the query , then the variables will be populated with values from the event record.

    Playbook EventRecords2

  5. Add or modify the values for the variables.

  6. Create a new investigation or add the guided query to an investigation.
    Create a New Investigation

    Select this option to create a new investigation. Enter the Investigation Name and Description.

    The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.

    Add to Existing Investigation

    From the Choose Investigation dropdown, select and investigation.

  7. Click Run Guided Queries.

Running a guided query of event records

Running a guided query of event records

To run a guided query of event records:
  1. Go to Investigations > Investigate and select an investigation from the list.

  2. Click View Results to view the investigation results.

  3. Right click on an entity to open the context menu and select Guided Queries.

    Playbooks

  4. Select a guided query from the list. If the event record has matching variables in the query , then the variables will be populated with values from the event record.

    Playbook EventRecords2

  5. Add or modify the values for the variables.

  6. Create a new investigation or add the guided query to an investigation.
    Create a New Investigation

    Select this option to create a new investigation. Enter the Investigation Name and Description.

    The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.

    Add to Existing Investigation

    From the Choose Investigation dropdown, select and investigation.

  7. Click Run Guided Queries.