Hello FortiSIEM Community,
I am working on a use case where I need to collect threat feed data from a 3rd party application and ingest it into the FortiSIEM platform. I came across the Python Threat Feed Framework, which mentions creating integrations for data collection.
However, I have some clarifications regarding my scenario. I have over more than 10 different threat lists, each with its own API. These threat lists contain various Indicators of Compromise (IoC), such as IPs, domains, URLs, and hashes, but the data is structured differently. Instead of having direct IoC information like IPs, domains, or hashes, each threat list provides its own unique API endpoint that returns a set of IoCs for that list.
Given this setup:
Any guidance on how to structure this integration or additional resources would be greatly appreciated!
Thanks in advance!
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
71 | |
24 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.