Hi all,
I want to pull alarms from a SIEM product that does not have a connector, and we will do this with the API. Will there be a duplicate alarm here, how can we prevent it, has anyone written a playbook about this before?
Hi,
not clear for me where could be the duplicate alarm.
If the FSR connector for your SIEM does not exist yet, you can simply use an API call as a step in a playbook to perform the relevant action.
Regards
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.