Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
venesa00
New Contributor

Quarantine a device from FortiAnalyzer playbooks

Hi!

I was wondering what changes do I have to make in my Fortigate, in the automation section, to automate the quarantine of an endpoint from FortiAnalyzer (with the playbook)?

I can run the playbooks to create incidents if it detects a compromised host, but I would like to quarantine them as well with another playbook. Do I have to create a sticth first on my Fortigate?

Thanks.

router login 192.168.l.l
2 REPLIES 2
gfleming
Staff
Staff
Jack_wack
New Contributor III

No, turning on the web hook in the FGT would be enough. Once it's done, new actions will show up in the FAZ under the fortiOS connector.

There is a playbook template for that.

 

Labels
Top Kudoed Authors