Skip to main content
nmathur
Staff
Staff
October 1, 2020

Unified Communications

  • October 1, 2020
  • 0 replies
  • 175 views

With the release of Content Pack (CP) 6.4.3, we are adding support for unified communications. It allows users to communicate with external entities, for example, tenant contacts, and other SOC teams, using email, instant messaging (IM), etc. from within an alert generated in FortiSOARâ„¢.

Note: CP-6.4.3 playbooks support email-based communications; the same can be extended for IM.

Configuration

Setting up a connector to send email

FortiSOARâ„¢ is deployed with pre-configured SMTP with local service postfix as the SMTP rely service. We recommend using the SMTP server that might be installed in your production setup or go for SMTP servers like smtp.google.com.

Alternatively, you can set up an Exchange connector to send emails. If you want to use the Exchange connector, then follow the steps mentioned in the following Configuring Playbooks section.

Setting Email Data Ingestion

Support for unified communications is added to the Data Ingestion Wizard for Exchange and IMAP connectors.

IMAP Connector version – 3.5.4-5893

Exchange Connector version – 3.4.3- 5919

While setting up data ingestion for IMAP or Exchange connectors, on the 'Configurations' page of the Data Ingestion Wizard, users should select the Use Unified Communications’ checkbox. This enables the required data ingestion workflows to maintain and track email communications for an alert. 


Note
: If the ‘Use Unified Communications’ checkbox is cleared, then data ingestion will not use unified communications and will work as normal email ingestion.

Configuring Playbooks

To set up an Exchange connector to send emails, do the following:

  1. From the left-navigation in FortiSOAR™, click Automation > Playbooks, and then select the 14 - Communications playbook collection. From this playbook collection, update the ‘Send Notification’ playbook to use either the SMTP or the Exchange connector to send emails.
    By default, the ‘Send Notification’ playbook is configured to use the SMTP connector.
  2. Click the Configuration step of the ‘Send Notification’ playbook, and update the value of the use_exchange_connector variable to true if you want to use the Exchange connector to send emails.
  3. Ensure that the Exchange connector has a valid 'Default Configuration'.

How To

Send an email from an alert

Open an alert in FortiSOARâ„¢ and click the Send Email button to send emails from an alert:


Clicking the Send Email button opens the Send Email dialog, where users can enter the details for the email and click Send to send the email.

When an email is sent, a record of this email is created in the "Communications" module and linked to the originating alert. Analysts can view the complete communications thread for the alert in the External Communications tab of an alert.

Receiving / Ingesting an email

Users have to set up email ingestion using either the Exchange or the IMAP connector. These connectors support unified communications usage.

  • Emails that are part of a thread that originated from an alert are automatically ingested and linked to the existing alert.
  • Emails that are not part of any existing email thread are ingested and converted into new alert records.

In both these cases, a communication record is created and linked to an alert for each email ingested:

Reply to a received email

When an email is received, it is auto-linked to an alert. Users can open emails from the External Communications tab in an alert record. This opens a communication record, which displays the details of the email.

Users can click on the Reply button and proceed to draft a reply.


An email sent as a reply is auto-linked to the alert record along with the communications record thereby preserving the email thread.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.