Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gmbpsupport
New Contributor

Reporting quarantine reasons, or export quarantine

New Fortimail customer here....still working on tweaking.

 

To help with the tweaking it would be great to have a way to report on WHY each message gets quarantined.  At minimum a way to export the system quarantine (released and unreleased) so I have a spreadsheet view and I can do a cross search and mark things up.

 

Any tips?  The fact that it is javascript gets annoying with copy\paste.

2 REPLIES 2
Carl_Windsor_FTNT

Why an email has been quarantined can be found by examining the X-Headers.  Are you looking for an explanation in the quarantine report itself and if so to what level?

[ul]
  • AV or AS
  • Exact method triggered[/ul]

    What are you looking to do with the System Quarantine list and what detail would you want to see in an export?  I have never seen a request for this before so am intrigued what the issue and purpose is for this.

     

  • Dr. Carl Windsor Field Chief Technology Officer Fortinet

    gmbpsupport

    We are getting a ton of false positives so I want to tweak it.

     

    I realize I can do a cross search and I get the reason for quarantine but that is on a one by one basis.  Ideally it would be great to get a report with reasons specific messages were quarantined so it can help us analyze what to tweak.  Make it a bit more purposeful than trial and error.

     

    The system quarantine is where all the quarantined items are.  If there is no way to generate the report that I'm interested in then what could be to list the messages out so I can at least fill in a spreadsheet of the quarantine reason only and not have to fill everything out.

    Labels
    Top Kudoed Authors