Fortinet white logo
Fortinet white logo

User Guide

Tag and comment events

Tag and comment events

Use the tag column to communicate with members of the security team about an event in an investigation. Tags and comments are viewable to any user with access to the investigation. You can use filters to view only tagged investigations or use the Search function to search for text in notes and comments.

To add a tag to an event:
  1. Do one of the following:

    • Click the Investigations tab, open an investigation and click View Results.

    • Go to Investigations > Private Search. In the Private Search tab, click View Results.

  2. Click the tag column next to the event. The Tag and Comment dialog opens.

  3. Select a tag from the dropdown.

  4. (Optional) Add a comment to the event.

  5. Click Save. The tag and comment icons are displayed in the tag column.

To remove a tag from an event:
  1. Click the tag column next to the event. The Tag and Comment dialog opens.

  2. Click Delete and then click Confirm in the dialog that opens.

Viewing and filtering tagged events

Tagged events are displayed in the Investigations and Private Search tabs. Hover over a tag to see an overview of the tagged events in the investigation.

To use tags and notes to filter investigations:
Option Description
Go to Investigations > Investigate
  1. Click the Filter icon.

  2. In the Tag section, select Tagged Investigations.
  3. (Optional) To refine results, select a tag label from the list (such as Evil).
  4. Click the investigation name.
  5. (Optional) Click Hide Notes to only see the tags.
  6. Click View Results.
Go to Investigations > Private Search
  1. Click the All Queries dropdown.
  2. In the Tag section, select Tagged Investigations.
  3. (Optional) To refine results, select a tag label from the list (such as Evil).
  4. Click View Results.

Go to Investigations

  1. Enter keywords in the Search field to search for text in comments and notes. Matching results are highlighted in yellow.
  2. Hover over the results in the Activities and Notes column.
    • Click a matched note to open the results table displaying the matched results.
    • Click View Details to open the investigation. The matched text will be highlighted.
Tooltip

After you filter the investigations, you can copy the URL to send the filtered view a member of your team.

Using tags to pivot to the events table

You can use a tagged event in the investigation dialog to quickly pivot to the Events table in an investigation. This function is available in the Dashboard, Investigations and Private Search pages. Click the tag icon in the tooltip.

The Events table will display the same number of events tagged in the investigation tooltip.

Tag and comment events

Tag and comment events

Use the tag column to communicate with members of the security team about an event in an investigation. Tags and comments are viewable to any user with access to the investigation. You can use filters to view only tagged investigations or use the Search function to search for text in notes and comments.

To add a tag to an event:
  1. Do one of the following:

    • Click the Investigations tab, open an investigation and click View Results.

    • Go to Investigations > Private Search. In the Private Search tab, click View Results.

  2. Click the tag column next to the event. The Tag and Comment dialog opens.

  3. Select a tag from the dropdown.

  4. (Optional) Add a comment to the event.

  5. Click Save. The tag and comment icons are displayed in the tag column.

To remove a tag from an event:
  1. Click the tag column next to the event. The Tag and Comment dialog opens.

  2. Click Delete and then click Confirm in the dialog that opens.

Viewing and filtering tagged events

Tagged events are displayed in the Investigations and Private Search tabs. Hover over a tag to see an overview of the tagged events in the investigation.

To use tags and notes to filter investigations:
Option Description
Go to Investigations > Investigate
  1. Click the Filter icon.

  2. In the Tag section, select Tagged Investigations.
  3. (Optional) To refine results, select a tag label from the list (such as Evil).
  4. Click the investigation name.
  5. (Optional) Click Hide Notes to only see the tags.
  6. Click View Results.
Go to Investigations > Private Search
  1. Click the All Queries dropdown.
  2. In the Tag section, select Tagged Investigations.
  3. (Optional) To refine results, select a tag label from the list (such as Evil).
  4. Click View Results.

Go to Investigations

  1. Enter keywords in the Search field to search for text in comments and notes. Matching results are highlighted in yellow.
  2. Hover over the results in the Activities and Notes column.
    • Click a matched note to open the results table displaying the matched results.
    • Click View Details to open the investigation. The matched text will be highlighted.
Tooltip

After you filter the investigations, you can copy the URL to send the filtered view a member of your team.

Using tags to pivot to the events table

You can use a tagged event in the investigation dialog to quickly pivot to the Events table in an investigation. This function is available in the Dashboard, Investigations and Private Search pages. Click the tag icon in the tooltip.

The Events table will display the same number of events tagged in the investigation tooltip.