Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dariopalermo
New Contributor

How to work with alerts and quarantine

Hi guys, I'm new to FortiClient and EMS and I'm lost. In any security system I've seen in the past:

1) I could acknowledge alerts

1) I could delete or recover quarantine files

 

Now in my brand new EMS I've got this client with 5 AV alerts and I cannot clear them up. If I go on the client and open the local FortiClient console, I found 6 threats (not 5) and 1 quarantined file (no info on the other threats). Delete and restore buttons grayed out. And I logged on the machine as a local Administrator.

 

What does I have to do to recover that file? (it's a false positive, identified as PossibleThreat)

 

thanks

 

Bye, Dario

1 REPLY 1
Boris_Rogalla
New Contributor

Hi dariopalermo,

 

I'm sorry not to be able to offer help, but I want to add a +1

as I am asking myself exactly the same questions.

 

We are evaluating EMS and Forticlient and have several Clients with false positives.

I have no idea how to manage this possible threads in EMS or on the client.

 

I can only hope it's a GUI-bug.

maybe someone can help?

Labels
Top Kudoed Authors