FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
FortiKoala
Staff
Staff
Article Id 196294
Description

How to save Alert events to a CSV file


Scope

FAQ


Solution

If you require a CSV of event information based on an ALERT:

  • Select the ALERTS tab on the ZoneFox menu.
  • Right click on the rule that you want to create the CSV file for (NB at the moment this will have to be performed for each user).
  • Select + Add Alert To Case





  • Either select an existing case or use the ADD TO NEW CASE button (bottom right) to create a new case.
    For this example, we will add to the existing case; select the case name then click on the FINISH button.








  • Hover over the CASES tab and select OPEN.  Double-click on your case, you should see the alerts that have previously added to the case.  If you click on the information button, the events associated with the alert will be displayed.







  • Select the DOWNLOAD button in the top right hand corner of the page.







  • Choose the CSV files radio button and DOWNLOAD.  This will download a zip file (for example zf-case-dfc38cfe.zip).







  • Unzip the file, there should be both an alerts and events csv file.  The alerts csv file will contain all the events for the alert that you selected and downloaded.



Contributors