FortiSOAR Discussions
gurveersingh
New Contributor

Ingest system alerts using FortiEDR Connector

Could we explore the possibility of adding functionality to ingest system alerts from FortiEDR into FortiSOAR? The FortiEDR API supports reading system events, which could be leveraged for this integration.

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/df7ab511-7435-11ea-9384-005056...

2 REPLIES 2
okumbhar
Staff
Staff

@gurveersingh we are already having a data ingestion to fetch events from FortiEDR and create alert in FortiSOAR

gurveersingh
New Contributor

@okumbhar Currently, the connector is capable of ingesting only security alerts. Can we add the capability to also ingest system alerts, which will provide insight into component health status?

 

Here is the sample API endpoint to which you can query to get system events

https://localhost/management-rest/system-events/list-system-events?componentNames=ensilo,USER-PC&com...