Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Soulaima
New Contributor

Can FortiSIEM Take Automated Actions Like an EDR or SOAR?

Hello everyone,

I'm currently working on my final year project, which involves Fortinet products, including FortiSIEM, as well as routers, switches, and endpoints.

I would like to understand more about FortiSIEM's capabilities when it comes to responding to security incidents. I have seen that FortiSIEM has remediation features, but I was told it doesn't support fully automated actions in response to security events.

Can FortiSIEM take automated actions similar to what an EDR or SOAR solution would do? For example, is it possible to:

  • Quarantine an endpoint?

  • Block a malicious IP address?

  • Kill a malicious process?

  • Isolate a machine from the network?

Or is FortiSIEM primarily focused on collecting logs and generating alerts, without taking direct action on network devices and endpoints automatically?

Any clarification or guidance on this would be greatly appreciated. Thank you!

1 Solution
AEK
SuperUser
SuperUser

Hi Soulaima

Here is an official response (from FSM datasheet).

 

Automated Incident Mitigation
When an Incident is triggered, an automated script can be run to mitigate or eliminate the threat. Built-in scripts support a variety of devices including Fortinet, Cisco, Palo Alto, and Window/Linux servers. Built-in scripts can execute a wide range of actions including disabling a user’s Active Directory account, disabling a switch port, blocking an IP address on a Firewall, deauthenticating a user on a WLAN Access Point, and more. Scripts leverage the credentials FortiSIEM already has in the CMDB. Administrators can easily extend the actions available by creating their own scripts.

 

However I know some companies prefer to integrate it with FortiSOAR for advanced response automation via playbooks instead of rules and scripts.

AEK

View solution in original post

AEK
1 REPLY 1
AEK
SuperUser
SuperUser

Hi Soulaima

Here is an official response (from FSM datasheet).

 

Automated Incident Mitigation
When an Incident is triggered, an automated script can be run to mitigate or eliminate the threat. Built-in scripts support a variety of devices including Fortinet, Cisco, Palo Alto, and Window/Linux servers. Built-in scripts can execute a wide range of actions including disabling a user’s Active Directory account, disabling a switch port, blocking an IP address on a Firewall, deauthenticating a user on a WLAN Access Point, and more. Scripts leverage the credentials FortiSIEM already has in the CMDB. Administrators can easily extend the actions available by creating their own scripts.

 

However I know some companies prefer to integrate it with FortiSOAR for advanced response automation via playbooks instead of rules and scripts.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors