#FortiSIEM
Use FortiSIEM v2 to fetch and update incidents, search events and manage watchlists of FortiSIEM.
FortiSIEM
- Details
- Content
- Dependencies
- Version History
Search and update events of FortiSIEM and manage resource lists.
#FortiSIEM
Use FortiSIEM v2 to fetch and update incidents, search events and manage watchlists of FortiSIEM.
Name | Description |
---|---|
FortiSIEM v2 |
Name | Description |
---|---|
FortiSIEM Status | |
FortiSIEM Attack Tactics | |
FortiSIEM Event Type | |
FortiSIEM Resolution Status | |
FortiSIEM Events | |
FortiSIEM Events Count | |
FortiSIEM Destination User | |
FortiSIEM Incident Last Seen | |
FortiSIEM Incident Severity | |
FortiSIEM Incident Reporter IP | |
FortiSIEM Incident Report Device Name | |
FortiSIEM Incident ID | |
FortiSIEM Incident First Seen |
Name | Description |
---|---|
FortiSIEM |
Name | Description |
---|---|
FortiSIEM v2 | Use FortiSIEM v2 to fetch and update incidents, search events and manage watchlists of FortiSIEM. |
FortiSIEM | Search and update events of FortiSIEM and manage resource lists. |
Name | Description |
---|---|
FortiSIEM incident Layout |
Name | Description |
---|---|
GenericPolling-FortiSIEM | This playbook executes a search query to retrieve FortiSIEM Events. |
Name | Description |
---|---|
FortiSIEM v2 |
Name | Description |
---|---|
FortiSIEM Incident Last Seen | |
FortiSIEM Incident ID | |
FortiSIEM Incident Reporter IP | |
FortiSIEM Incident Report Device Name | |
FortiSIEM Resolution Status | |
FortiSIEM Incident Severity | |
FortiSIEM Destination User | |
FortiSIEM Events Count | |
FortiSIEM Events | |
FortiSIEM Attack Tactics | |
FortiSIEM Status | |
FortiSIEM Event Type | |
FortiSIEM Incident First Seen |
Name | Description |
---|---|
FortiSIEM |
Name | Description |
---|---|
FortiSIEM v2 | Use FortiSIEM v2 to fetch and update incidents, search events and manage watchlists of FortiSIEM. |
FortiSIEM | Search and update events of FortiSIEM and manage resource lists. |
Name | Description |
---|---|
GenericPolling-FortiSIEM | This playbook executes a search query to retrieve FortiSIEM Events. |
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Common Playbooks | By: Cortex XSOAR |
Filters And Transformers | By: Cortex XSOAR |
Pack Name | Pack By |
---|---|
Common Types | By: Cortex XSOAR |
Pack Name | Pack By |
---|---|
Filters And Transformers | By: Cortex XSOAR |
Cortex REST API | By: Cortex XSOAR |
Base | By: Cortex XSOAR |
Common Playbooks | By: Cortex XSOAR |
Rasterize | By: Cortex XSOAR |
Integrations
FortiSIEM v2
- Updated the integration documentation to clarify that the Fetch with Events fetch mode, as well as the fortisiem-event-search command, are supported only for FortiSiem version 6.6 and earlier due to changes affecting backward compatibility in subsequent versions of FortiSiem.
- 35917
Download
Integrations
Google Sheets
- Updated formatting of integration parameters.
Integrations
FortiSIEM
- Updated the Docker image to: demisto/python:2.7.18.27799.
Incident Fields
- FortiSIEM Incident Last Seen
- FortiSIEM Incident First Seen
- FortiSIEM Event Type
- FortiSIEM Incident ID
- FortiSIEM Incident Reporter IP
- FortiSIEM Events
- FortiSIEM Incident Report Device Name
- FortiSIEM Events Count
- FortiSIEM Status
- FortiSIEM Destination User
- FortiSIEM Attack Tactics
- FortiSIEM Resolution Status
- FortiSIEM Incident Severity
Incident Types
- FortiSIEM
Integrations
FortiSIEM
- Updated formatting of integration parameters.
New: FortiSIEM v2
- Use FortiSIEM v2 to fetch and update incidents, search events and manage watchlists of FortiSIEM. (Available from Cortex XSOAR 6.0.0).
Layouts
- New: FortiSIEM incident Layout
- (Available from Cortex XSOAR 6.0.0).
Mappers
New: FortiSIEM v2
- (Available from Cortex XSOAR 6.0.0).
Playbooks
New: GenericPolling-FortiSIEM
- (Available from Cortex XSOAR 6.0.0).
Integrations
FortiSIEM
- Updated the Docker image to: demisto/python:2.7.18.24398.
PUBLISHER
PLATFORMS
INFO
Certification | Certified | Read more |
Supported By | Cortex | |
Created | November 9, 2020 | |
Last Release | November 20, 2024 |