FortiSIEM Discussions
Deepika
New Contributor

Incident closure

Hi Team,

 

I'm trying to identify where to check my resolved incidents in FortiSIEM. i would like to know where can i see all the resolved incidents closed by me/by my team

5 REPLIES 5
premchanderr
Staff
Staff

Hi @Deepika ,


You can run the System Report "All Incidents" and include display conditions Incident Status , Incident Resolution , Incident Cleared User etc

In this report to know all the available fields you can expand the blank raw event log in Analytics and view in Event Details. 

Regards,
Prem Chander R
Deepika
New Contributor

could you help me with the navigation ? where can i see system report option in fortisiem

 

premchanderr

Sure Deepika, Login Fortisiem GUI > Resources > Reports . Here search for - All Incidents .

Regards,
Prem Chander R
Deepika

thanks for the update. where can i export the data's ? for example i would like to export all the events for a incident how can i do that

cdurkin_FTNT

Probably the easiest way is from the Incident Tab itself.

 

1) Select the Incident

2) Select Actions -> Export Incident

3) Choose PDF or CSV and tick "Include Raw Event Message"