Fortinet white logo
Fortinet white logo

User Guide

Working with Analytics Search

Working with Analytics Search

FortiSIEM search functionality includes real time and historical search of information that has been collected from your IT infrastructure. With real time search, you can see events as they happen, while historical search is based on information stored in the event database. Both types of search include simple keyword searching, and structured searches that let you search based on specific event attributes and values, and then group the results by attributes.

Note: If Data Obfuscation is turned on for a FortiSIEM user:

  • The value for that object marked for data obfuscation is obfuscated. For example, if IP is marked for data obfuscation, the IP address is obfuscated. In earlier versions of FortiSIEM, raw events were completely obfuscated.

  • CSV Export feature is disabled.

The following sections provide information about the operations under ANALYTICS tab:

Working with Analytics Search

Working with Analytics Search

FortiSIEM search functionality includes real time and historical search of information that has been collected from your IT infrastructure. With real time search, you can see events as they happen, while historical search is based on information stored in the event database. Both types of search include simple keyword searching, and structured searches that let you search based on specific event attributes and values, and then group the results by attributes.

Note: If Data Obfuscation is turned on for a FortiSIEM user:

  • The value for that object marked for data obfuscation is obfuscated. For example, if IP is marked for data obfuscation, the IP address is obfuscated. In earlier versions of FortiSIEM, raw events were completely obfuscated.

  • CSV Export feature is disabled.

The following sections provide information about the operations under ANALYTICS tab: