Fortinet white logo
Fortinet white logo

Administration Guide

All Events

All Events

To view all the events, go to FortiSoC/Incidents & Events > Event Monitor > All Events.

Double-click an event line to drill down for more details.

Hover your mouse over an entry to view the asset and identity information for that event.

You can perform the following actions from the toolbar:

Save as New Custom View

Save the current view including filter settings, device selection, and time period.

Devices

Select devices from the dropdown to filter the table view.

Time Period

Select a time period to filter the table view. Select Custom to specify a time period not in the dropdown list.

Show Acknowledged

Click to include acknowledged events in the table view. See Acknowledging events.

Collapse All/Expand All

Click to expand or collapse the event details displayed in the table view.

Refresh

Click to manually refresh the table view.

Alternatively, from the dropdown, you can specify an automatic refresh interval for the table view.

Export to CSV

Click to download the current table view of events in a CSV file.

Filters

Enter filters for the table view. See Filtering events.

Column Settings

Select which columns are displayed for the table view.

By right-clicking an event in the table view, you can perform the following actions from the shortcut menu:

Acknowledge

Acknowledge the event. See Acknowledging events.

Comment

Enter a comment for the event. The comment is displayed in the Comment column, which can be added to the table view from Column Settings.

Assign To

Select an admin to assign the event to. The assigned admin is displayed in the Assigned To column, which can be added to the table view from Column Settings.

View Logs

Open a table view of sampled logs associated with the event.

For example, if there are 20 associated logs that triggered the event under the same conditions, only one sample log display in the View Logs pane. To view all logs associated with the event, use Search in Log View.

Search in Log View

Open Log View in a separate tab, filtered to display all logs associated with the event.

Create New Incident

Create a new incident from the event. See Raising an incident.

Add to Existing Incident

Attach the event to an existing incident. In the Attach to Incident dialog, enter an incident number or select an incident from the table and click OK.

Filter by <criteria> =

Filter for events that are equal to the criteria that you right-clicked in the table view. See Filtering events.

Filter by <criteria> !=

Filter for events that are not equal to the criteria that you right-clicked in the table view. See Filtering events.

All Events

All Events

To view all the events, go to FortiSoC/Incidents & Events > Event Monitor > All Events.

Double-click an event line to drill down for more details.

Hover your mouse over an entry to view the asset and identity information for that event.

You can perform the following actions from the toolbar:

Save as New Custom View

Save the current view including filter settings, device selection, and time period.

Devices

Select devices from the dropdown to filter the table view.

Time Period

Select a time period to filter the table view. Select Custom to specify a time period not in the dropdown list.

Show Acknowledged

Click to include acknowledged events in the table view. See Acknowledging events.

Collapse All/Expand All

Click to expand or collapse the event details displayed in the table view.

Refresh

Click to manually refresh the table view.

Alternatively, from the dropdown, you can specify an automatic refresh interval for the table view.

Export to CSV

Click to download the current table view of events in a CSV file.

Filters

Enter filters for the table view. See Filtering events.

Column Settings

Select which columns are displayed for the table view.

By right-clicking an event in the table view, you can perform the following actions from the shortcut menu:

Acknowledge

Acknowledge the event. See Acknowledging events.

Comment

Enter a comment for the event. The comment is displayed in the Comment column, which can be added to the table view from Column Settings.

Assign To

Select an admin to assign the event to. The assigned admin is displayed in the Assigned To column, which can be added to the table view from Column Settings.

View Logs

Open a table view of sampled logs associated with the event.

For example, if there are 20 associated logs that triggered the event under the same conditions, only one sample log display in the View Logs pane. To view all logs associated with the event, use Search in Log View.

Search in Log View

Open Log View in a separate tab, filtered to display all logs associated with the event.

Create New Incident

Create a new incident from the event. See Raising an incident.

Add to Existing Incident

Attach the event to an existing incident. In the Attach to Incident dialog, enter an incident number or select an incident from the table and click OK.

Filter by <criteria> =

Filter for events that are equal to the criteria that you right-clicked in the table view. See Filtering events.

Filter by <criteria> !=

Filter for events that are not equal to the criteria that you right-clicked in the table view. See Filtering events.