Working with Analytics Search
FortiSIEM search functionality includes real time and historical search of information that has been collected from your IT infrastructure. With real time search, you can see events as they happen, while historical search is based on information stored in the event database. Both types of search include simple keyword searching, and structured searches that let you search based on specific event attributes and values, and then group the results by attributes.
Note: If Data Obfuscation is turned on for a FortiSIEM user:
The value for that object marked for data obfuscation is obfuscated. For example, if IP is marked for data obfuscation, the IP address is obfuscated. In earlier versions of FortiSIEM, raw events were completely obfuscated.
- CSV Export feature is disabled.
The following sections provide information about the operations under ANALYTICS tab:
- Executing a Playbook
- Running a Connector
- Running a Built-in Search
- Understanding Search Components
- Viewing Historical Search Results
- Viewing Real-time Search Result
- Using Nested Queries
- Searches Using Pre-computed Results
- Saving Search Results
- Viewing Saved Search Results, Loading Reports and Shortcuts
- Exporting Search Results
- Emailing Search Results
- Creating a Rule from Search
- Copying Filter and Time Range Tab Information
- Fortinet Advisor