- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiSIEM to SOAR
Hi guys,
I am trying to integrate FortiSIEM with Soar. I have a multitenant structure in SIEM and logs come here. When I enter the name in the organisation tenant structure in the Soar integration, I get an error in the healtcheck section, but when I enter Super, I do not encounter a problem, but this time I cannot pull it to Soar because there is no log in the Super section.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Are you able to login to the FortiSIEM UI using the same creds and organisation?
Ensure the user which you are trying to authenticate belong to that organisation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I can see it and I can log in with it. I get confirmation with this credential information on Soar, but when I trigger it, it gives an error in the playbook.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please share the logs and screenshot of the error you are encountering?
Also need the details like the FortiSOAR version, FortiSIEM connector version, and FortiSIEM setup version?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've soar 7.4.0 version, also connector 7.0.2 version.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. Please check the mapping for the Tenant in the Create Record step:
2. Check the { FortiSIEM Organisation : FortiSOAR Tenant } mapping on the Data Ingestion configuration page.
3. Also, any modification in the Alerts Module may have caused this issue.
For deeper troubleshooting, we'll need logs from various services. Feel free to raise a ticket with our TAC/Support team for assistance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry for the late reply, I could not see your answer. I've checked the my configuration. I'm not sure if I should change the name of the organisation here.
Created on ‎02-14-2024 10:37 PM Edited on ‎02-14-2024 10:45 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @adem_netsys,
I recommend raising a TAC ticket with our support team.
After reviewing the error message, It seems to have originated from the platform level. That would require getting hold of your environment and gather various logs.
Contact FortiCare Technical Support
