All Events
To view all the events, go to FortiSoC/Incidents & Events > Event Monitor > All Events.
Double-click an event line to drill down for more details.
Hover your mouse over an entry to view the asset and identity information for that event.
You can perform the following actions from the toolbar:
Save as New Custom View |
Save the current view including filter settings, device selection, and time period. |
Devices |
Select devices from the dropdown to filter the table view. |
Time Period |
Select a time period to filter the table view. Select Custom to specify a time period not in the dropdown list. |
Show Acknowledged |
Click to include acknowledged events in the table view. See Acknowledging events. |
Collapse All/Expand All |
Click to expand or collapse the event details displayed in the table view. |
Refresh |
Click to manually refresh the table view. Alternatively, from the dropdown, you can specify an automatic refresh interval for the table view. |
Export to CSV |
Click to download the current table view of events in a CSV file. |
Filters |
Enter filters for the table view. See Filtering events. |
Column Settings |
Select which columns are displayed for the table view. |
By right-clicking an event in the table view, you can perform the following actions from the shortcut menu:
Acknowledge |
Acknowledge the event. See Acknowledging events. |
Comment |
Enter a comment for the event. The comment is displayed in the Comment column, which can be added to the table view from Column Settings. |
Assign To |
Select an admin to assign the event to. The assigned admin is displayed in the Assigned To column, which can be added to the table view from Column Settings. |
View Logs |
Open a table view of sampled logs associated with the event. For example, if there are 20 associated logs that triggered the event under the same conditions, only one sample log display in the View Logs pane. To view all logs associated with the event, use Search in Log View. |
Search in Log View |
Open Log View in a separate tab, filtered to display all logs associated with the event. |
Create New Incident |
Create a new incident from the event. See Raising an incident. |
Add to Existing Incident |
Attach the event to an existing incident. In the Attach to Incident dialog, enter an incident number or select an incident from the table and click OK. |
Filter by <criteria> = |
Filter for events that are equal to the criteria that you right-clicked in the table view. See Filtering events. |
Filter by <criteria> != |
Filter for events that are not equal to the criteria that you right-clicked in the table view. See Filtering events. |