Skip to main content
hard2know
New Member
January 9, 2020
Question

Automation stitches and IPS

  • January 9, 2020
  • 1 reply
  • 3458 views

Is it possible to send IPS logs/alerts to webhook using automation stitches?

I search thru all "Events" in trigger "FortiOS Event Log" and didn't find any events connected to IPS alerts :(

 

    1 reply

    nostalia_nse7
    New Member
    January 23, 2020

    Have you looked into the integration with FortiAnalyzer; and whether you can trigger FAZ to cause a "Compromised Host" alert or something?  Sorry haven't played with Stitches much yet.  My use case for IPS Triggers has been having a script parse the email notifications, get the source IPs, then dumping them to a text file on a web server; then using the External List fabric connector to import the addresses into an address object used in a Deny policy ahead of my VIPs / other rules where appropriate.