FortiSIEM Converting an Historical Search to a Real Time Search

Converting an Historical Search to a Real Time Search

In the course of running an historical search, you may produce results that you want to examine in real time. For example, suppose that an historical search shows that yesterday there was an excessive amount of outgoing traffic from your home country or countries that you do business with. You may want to know if this same traffic pattern is happening right now, in real time. You can answer this question from within the same historical search that raised your suspicions.

  1. In the historical search window, click Real Time Search.

The historical search criteria are loaded into a Real Time Search window and begin to execute.

  1. You can now refine your Real Time Search results to reflect your current interest, for example by adding a Destination County attribute to the display results and running the search again.
This entry was posted in Administration Guides, FortiSIEM on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.