Fortinet black logo

User Guide

Start an investigation

Start an investigation

To start an investigation:
  1. Go to Detections > Triage Rules. The Detections Rules page opens.
  2. Click a rule to open the Details page.
  3. Click Start Investigation. The Add Query to Investigation dialog opens.

    Query NameEnter a name for the query.
    Search QueryEnter the query string.
    Last 7 DaysClick to set the data range to Last Hour, Last 24 Hours, Last 7 days, Last 30 days, Last 60 days or last 90 days.
    Sort by timestamp Select Ascending or Descending.
    Retrieve up to Click to set the number of rows retrieved (100, 500, 1000, or 10,000).
    Create a New InvestigationClick to create a new investigation.
    Add to Existing InvestigationThe Choose Investigation dropdown is displayed. Select an investigation from the list.

    Run a Private Query

    Select this option to add a query to an adhoc search.

    Investigation NameEnter a name for the new investigation.

    Description

    Enter a short description of the new investigation.

    Choose Investigation

  4. Click Add Query.

Start an investigation

To start an investigation:
  1. Go to Detections > Triage Rules. The Detections Rules page opens.
  2. Click a rule to open the Details page.
  3. Click Start Investigation. The Add Query to Investigation dialog opens.

    Query NameEnter a name for the query.
    Search QueryEnter the query string.
    Last 7 DaysClick to set the data range to Last Hour, Last 24 Hours, Last 7 days, Last 30 days, Last 60 days or last 90 days.
    Sort by timestamp Select Ascending or Descending.
    Retrieve up to Click to set the number of rows retrieved (100, 500, 1000, or 10,000).
    Create a New InvestigationClick to create a new investigation.
    Add to Existing InvestigationThe Choose Investigation dropdown is displayed. Select an investigation from the list.

    Run a Private Query

    Select this option to add a query to an adhoc search.

    Investigation NameEnter a name for the new investigation.

    Description

    Enter a short description of the new investigation.

    Choose Investigation

  4. Click Add Query.