Description | This article describes how to configure remediation using FortiGate REST API scripts for a device in the case of an incident. The remediation script to be used is: 'Block Source IP FortiOS 7.x via FortiOS API' but remediation will use the HTTPS access protocol and NOT the FORTIOS_REST_API access protocol. |
Scope | FortiSIEM, FortiGate. |
Solution |
To create a REST API Token on FortiGate, see the following documentation: Connect Fortigate Device via API Token.
Step 1: Configure Credentials for FortiGate to be used for remediation. Follow these steps:
Name: <credentials_name>
Test the credentials:
Testing:
|