FortiSIEM Discussions
Kunj
New Contributor

IoC External Lookup

I have a use case where I need to make an integration to perform an external lookup on IoC in incidents in FortiSIEM. When the user clicks on any column/field in incident, the lookup should be performed.

 

1. How will FortiSIEM recognize which incident field (IoC) to be enriched and how does it pass the field data to integration policy for external lookup?

2. Is FortiSIEM able to categorize whether the IoC is IP, URL, Domain or File Hash?

3. How do I create an external lookup for an integration to make an API call to third party app and store the response in Lookup Table?

0 REPLIES 0
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"