I have a use case where I need to make an integration to perform an external lookup on IoC in incidents in FortiSIEM. When the user clicks on any column/field in incident, the lookup should be performed.
1. How will FortiSIEM recognize which incident field (IoC) to be enriched and how does it pass the field data to integration policy for external lookup?
2. Is FortiSIEM able to categorize whether the IoC is IP, URL, Domain or File Hash?
3. How do I create an external lookup for an integration to make an API call to third party app and store the response in Lookup Table?
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.