In a #Fortinet #FortiSOAR multi-tenant environment, a single tenant's
misconfigured Security Information and Event Management (#SIEM)
detection rule can generate an excessive volume of events or alerts.
This results in a substantial backlog of tasks ...
We have automation workflow where heavy use of find / search step is
used with combination of on-create step, to correlate similar alerts and
process alerts with a reference to predefined closer workflow. Can we
have another read only Postgresql data...
Hello FortiSOAR Experts, What are supported 3rd party secret vaults
solutions that is compatible with FortiSOAR's Password Vault feature
from below list? Refer to password vault feature documentation :
https://docs.fortinet.com/document/fortisoar/7.6...
Hello FortiSOAR Experts. Please suggest - whether a 3 node HA cluster,
where 2 nodes are in HA Active/Active and the 3rd node is HA Passive in
DR site is achievable when POSTGRESQL is externalized separately for
MAIN site and DR site. How the POSTGRE...
Hello FortiSOAR Experts. Mismatch connector version in content hub page
vs playbook.Can you please suggest the reason behind it and the solution
? Can we run content hub force sync safely, without affecting anything ?
Dear @kaashif_m I WANTED TO CLARIFY THAT THE ISSUE AT HAND IS NOT
RELATED TO FORTISIEM OR SEARCHING EVENTS FOR AN ALERT. UNFORTUNATELY,
THE RESPONSES PROVIDED SO FAR HAVE NOT ADDRESSED THE CORE OF THE
PROBLEM. THANK YOU FOR YOUR UNDERSTANDING. Thanks...
Dear @kaashif_m Thank you for your reply. However, the issue is not
searching co-related events from SIEM.My above-described issue is for
very initial ingestion playbook, and I am talking about 10000 alerts
getting ingested in 1 hour, due to a miscon...
This is very interesting use-case to use AI/ML for phishing email
automatic detection using SOAR by ingesting and parsing each and every
email body. Let's hope FortiSOAR comes up with this feature first than
anyone else.
Any update for my request ? Please let me know if there is POC
environment 3 instances of FortiSOAR (production, staging and
development) , where I can remotely login and test the CICD solution
pack. Thanks