Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Quarantine a device from FortiAnalyzer playbooks
Hi!
I was wondering what changes do I have to make in my Fortigate, in the automation section, to automate the quarantine of an endpoint from FortiAnalyzer (with the playbook)?
I can run the playbooks to create incidents if it detects a compromised host, but I would like to quarantine them as well with another playbook. Do I have to create a sticth first on my Fortigate?
Thanks.
router login 192.168.l.l
Labels:
- Labels:
-
FortiAnalyzer
2 REPLIES 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Lots of good info here: https://docs.fortinet.com/document/fortianalyzer/7.2.2/administration-guide/691884/configuring-playb...
Cheers,
Graham
Graham
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, turning on the web hook in the FGT would be enough. Once it's done, new actions will show up in the FAZ under the fortiOS connector.
There is a playbook template for that.
