Description |
Remediation script on FortiSIEM for FortiMail provides a remediation action on incident. This article describes the configuration on FortiMail and in FortiSIEM. |
Scope | FortiMail, FortiSIEM, Remediation. |
Solution |
In FortiSIEM it is necessary declare the Access Method for FortiMail:
Note: The URI should be empty. In the Device credential association, create the association using the FQDN to verify the SSL certificate. The test connectivity should be successful.
Remediation scripts: FortiMail remediation is located under /opt/phoenix/data-definition/remediations. The scripts makes 2 API calls when triggered:
config system web-service
The username used to connect must have REST access:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.