With the case revamp on fortiSIEM 7.2.0, there was a need to have users in the "FortiSIEM Analysts", which seemed to work fine. Until the group was magically empty after a while.
It seems that our scheduled discovery for LDAP are moving users back from the builtin group "FortiSIEM Analysts" to the group created by discovery (see image below).
Is this fixable, or is the workaround just creating local users so that cases can be created?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @nisse ,
This is by design and currently no workaround . The AD user would be removed from FortiSIEM Analysts group even if you move manually upon re-discovering.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.