FortiSIEM Creating a Simple Historical Search

Creating a Simple Historical Search




If you need to familiarize yourself with how historical search works or the historical search interface, you should read these topics:

Overview of the Historical Search User Interface

Example of How a Structured Historical Search is Processed

Sample Historical Searches

Structured Search Operators


  1. Log in to your Supervisor node.
  2. Go to Analytics > Historical Search.
  3. For Filter Criteria, select Simple.
  4. Enter the keywords you want to search for in the raw event logs.

See Keywords and Operators for Simple Searches for information on keyword searching.

  1. Under Display Fields, select the attributes you want to use as the columns in your results list.

See Selecting Attributes for Structured Searches, Display Fields, and Rules and Creating Filter Criteria and Display Column Sets for options for selecting display field attributes and sets.

  1. For Time, set the interval over which you want the search to run.
  2. For multi-tenant deployments, select the Organization you want to run the search against.
  3. Click Run.

The results of your search will be displayed in the chart and search results list.



Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

Don't Forget To visit the YouTube Channel for the latest Fortinet Training Videos and Question / Answer sessions!
- FortinetGuru YouTube Channel
- FortiSwitch Training Videos