FortiEDR
FortiEDR automates the protection against advanced threats, pre and post-execution, with real time orchestrated incident response functionality.
ymasaki
Staff
Staff
Article Id 325307
Description This article describes how to locate blocked processes in Event Viewer using the event's Raw ID in the FortiEDR Collector Tray App.
Scope FortiEDR/
Solution

FortiEDR collector has the option to notify users with a pop-up message when any prevention activity is detected.

This message contains details about the blocked process including PID and relevant messages.

 

collector_event0.png

 

The PID is specific to the detected process managed by the machine and it is not sent to the Central Manager. For this reason, the blocked event cannot be found in the Event Viewer when searching with the PID.

 

To locate the detected events in Event Viewer, you need to use the RAW ID to search for the matched events.

 

Steps to Locate Events in Event Viewer Based on the RAW ID in FortiEDR Tray App:

  1. Note the process and PID from the pop-up message.

 

collector_event0_pid.png

 

  1. 'Double-click' the FortiEDR icon in the system tray to open the FortiEDR Tray App:

 

collector_event_tray.png

 

  1. Identify the detected event based on PID and note the RAW ID:

 

collector_event0_rawid.png

 

  1. Go to the Event Viewer to search the RAW ID and locate the corresponding events:

 

collector_event2.png

 

  1. If the event is not found in the All view, switch to the Archived view (All view does not include Archived events):

 

collector_event3.png

 

Note:

The option 'Show a Pop-up Message for Any Prevention Activity' must be enabled to display a pop-up message.

For more information about the setting, visit End-user notifications

Contributors