Hello everyone,
I'm currently working on my final year project, which involves Fortinet products, including FortiSIEM, as well as routers, switches, and endpoints.
I would like to understand more about FortiSIEM's capabilities when it comes to responding to security incidents. I have seen that FortiSIEM has remediation features, but I was told it doesn't support fully automated actions in response to security events.
Can FortiSIEM take automated actions similar to what an EDR or SOAR solution would do? For example, is it possible to:
Quarantine an endpoint?
Block a malicious IP address?
Kill a malicious process?
Isolate a machine from the network?
Or is FortiSIEM primarily focused on collecting logs and generating alerts, without taking direct action on network devices and endpoints automatically?
Any clarification or guidance on this would be greatly appreciated. Thank you!
Solved! Go to Solution.
Hi Soulaima
Here is an official response (from FSM datasheet).
Automated Incident Mitigation
When an Incident is triggered, an automated script can be run to mitigate or eliminate the threat. Built-in scripts support a variety of devices including Fortinet, Cisco, Palo Alto, and Window/Linux servers. Built-in scripts can execute a wide range of actions including disabling a user’s Active Directory account, disabling a switch port, blocking an IP address on a Firewall, deauthenticating a user on a WLAN Access Point, and more. Scripts leverage the credentials FortiSIEM already has in the CMDB. Administrators can easily extend the actions available by creating their own scripts.
However I know some companies prefer to integrate it with FortiSOAR for advanced response automation via playbooks instead of rules and scripts.
Hi Soulaima
Here is an official response (from FSM datasheet).
Automated Incident Mitigation
When an Incident is triggered, an automated script can be run to mitigate or eliminate the threat. Built-in scripts support a variety of devices including Fortinet, Cisco, Palo Alto, and Window/Linux servers. Built-in scripts can execute a wide range of actions including disabling a user’s Active Directory account, disabling a switch port, blocking an IP address on a Firewall, deauthenticating a user on a WLAN Access Point, and more. Scripts leverage the credentials FortiSIEM already has in the CMDB. Administrators can easily extend the actions available by creating their own scripts.
However I know some companies prefer to integrate it with FortiSOAR for advanced response automation via playbooks instead of rules and scripts.
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.