Question
FortiSiem Recover data from SQL DB
Hi everyone;
I still have an incident (backdoor found) appearing on the Fortisiem console, the source of this incident is the IPS of the Fortigate Firwall which detects traffic coming from internal clients towards malicious links.
My need is as follows:
I want to create a rule (or an costum event) which will search the SQL database of the antivirus solution server, in order to confirm whether this client has an antivirus agent or not.
How can the SIEM query and retrieve data from this database?
