FortiSIEM Discussions
amiranda
Staff
Staff

Google SecOPs Soar integration with FortiSiem Cloud

I have a customer using FortiSiem Cloud version 7.3.4, the customer wants to integrate Google Soar via API with FortiSiem, there is documentation from google regarding this integration:

 

https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/fortinet-fortisiem?hl=es-419

 

We created a user with full admin permission, but when we try  the connection from google Soar we see a 401 not authorized response, according the fortisiem cloud documentation the API is supported with some restrictions.

 

Differences between FortiSIEM Cloud and FortiSIEM | FortiSIEM Cloud | Fortinet Document Library

 

I would like to know if someone have done this integration in the past, and maybe what are we missing in the configuration.

 

 

amiranda
1 Solution
igtaveras
Staff
Staff

This since like an authentication issue when trying to consume API services. This issue happens because the user credentials are not specifying the organization. Regardless of the implementation (Enterprise or Service Provider) you need to specify the organization in the user section when you try to consume API services from FSM platform.

 

For a Enterprise implementation "super" will always be the organization.  Example: super/admin. With that change you should be able to complete the integration.

Ignacio Taveras

View solution in original post

1 REPLY 1
igtaveras
Staff
Staff

This since like an authentication issue when trying to consume API services. This issue happens because the user credentials are not specifying the organization. Regardless of the implementation (Enterprise or Service Provider) you need to specify the organization in the user section when you try to consume API services from FSM platform.

 

For a Enterprise implementation "super" will always be the organization.  Example: super/admin. With that change you should be able to complete the integration.

Ignacio Taveras