Created on ‎02-22-2024 09:11 PM
To integrate FortiSOAR Threat Intelligence Management (TIM) with FortiSIEM, you can leverage the following approach. While FortiSIEM may not support STIX format, it does support CSV integration.
For successful integration, use the following URL format:
https://<FortiSOAR.IP>/api/taxii/1/collections/<DatasetID>/objects?$format=csv&$__selectFields=value&$limit=10000 |
Ensure to filter the CSV using the field "Value" with the following parameter:
$__selectFields=value
It's worth noting that for IP addresses, you may encounter one invalid row, but this is acceptable in the integration process.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.