FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
FortiKoala
Staff
Staff
Article Id 192161
Description

What is an Investigation


Scope

Key Concepts


Solution

An Investigation within ZoneFox is a way of collating related alerts together and adding notes to help you compile a record of a forensic investigation.


Investigations belong to a particular user on the system, although ownership of an Investigation can be transferred to another ZoneFox user by editing the investigation.


Notes can be added to an Investigation to provide comments and context around the alerts which have been recorded.


The status of an Investigation can be changed to closed, or marked as reported / not requiring further action.


Contributors