Description | This article describes how to locate blocked processes in Event Viewer using the event's Raw ID in the FortiEDR Collector Tray App. |
Scope | FortiEDR/ |
Solution |
FortiEDR collector has the option to notify users with a pop-up message when any prevention activity is detected. This message contains details about the blocked process including PID and relevant messages.
The PID is specific to the detected process managed by the machine and it is not sent to the Central Manager. For this reason, the blocked event cannot be found in the Event Viewer when searching with the PID.
To locate the detected events in Event Viewer, you need to use the RAW ID to search for the matched events.
Steps to Locate Events in Event Viewer Based on the RAW ID in FortiEDR Tray App:
Note: The option 'Show a Pop-up Message for Any Prevention Activity' must be enabled to display a pop-up message. For more information about the setting, visit End-user notifications |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.