Description This article describes how to fix an issue that occurs after
the API endpoints change at the CrowdStrike end. Scope FortiSOAR,
CrowdStrike Falcon Connector. Solution The following API Endpoints are
going to be deprecated by CrowdStrike, w...
Description This article describes how to fix the package version
conflict issue that occurs during the FortiSOAR upgrade. Scope FortiSOAR
v7.3 deployed on an Azure host system. Solution FortiSOAR upgrade from
v7.3.0 to v7.4 fails with below error du...
Description This article describes how to fix an issue where the Python
library failed to install during FortiSOAR's initial configuration Scope
FortiSOAR. Solution After installing FortiSOAR, the initial config
wizard launches to configure it once t...
Description This article describes how to fix the issue that occurs
during content export while using the Export Wizard option. Scope
FortiSOAR. Solution While exporting the contents like connectors,
playbook, and other modules, it fails with the bel...
Description This article describes how to resolve an issue that occurs
after upgrading the FortiGate connector to version 5.4.0. Scope
FortiSOAR and FortiGate Connector version 5.4.0 Solution Issue 1: After
upgrading the FortiGate connector to the 5....
Hello @adem_netsys As discussed, the issue was resolved after updating
the playbook IRI value in the global variable "IP_Enrichment_IRI," which
determines the playbooks that need to be executed to enrich the IP
address.
Hello @ranjeet, the output is displayed in the UTC timezone. FortiSOAR
takes input based on the local system's timezone with 12 AM time, but
the output is displayed in UTC (-5:30H), hence it shows a different
date.
Hello @khilfi Kindly refer to the section "Data Ingestion Support" in
the document below:
https://docs.fortinet.com/document/fortisoar/5.4.1/fortinet-fortisiem/1059/fortinet-fortisiem-v5-4-1#dataIngestionYou
can map the fields extracted from the sour...
You can review the execution history for the alert to identify the
reason for the playbook failure, which should help pinpoint the root
cause.If the playbook has failed, you can also try retriggering it.
Hello @Osama-Ahmed The indicator extraction for the alert seems stuck or
is still in progress. You can check the Extration playbook status by
opening an alert and selecting the playbook execution history for the
respective alert. Regarding the second...