FortiSIEM Creating a Simple Historical Search

Creating a Simple Historical Search

Prequisites

Procedure

Prequisites

If you need to familiarize yourself with how historical search works or the historical search interface, you should read these topics:

Overview of the Historical Search User Interface

Example of How a Structured Historical Search is Processed

Sample Historical Searches

Structured Search Operators

Procedure

  1. Log in to your Supervisor node.
  2. Go to Analytics > Historical Search.
  3. For Filter Criteria, select Simple.
  4. Enter the keywords you want to search for in the raw event logs.

See Keywords and Operators for Simple Searches for information on keyword searching.

  1. Under Display Fields, select the attributes you want to use as the columns in your results list.

See Selecting Attributes for Structured Searches, Display Fields, and Rules and Creating Filter Criteria and Display Column Sets for options for selecting display field attributes and sets.

  1. For Time, set the interval over which you want the search to run.
  2. For multi-tenant deployments, select the Organization you want to run the search against.
  3. Click Run.

The results of your search will be displayed in the chart and search results list.

 

 

This entry was posted in Administration Guides, FortiSIEM on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.