Fortinet Playbook Deployment

rob wood 41 Reputation points
2024-03-15T13:12:51.48+00:00

Hello,

Has anyone managed to create the three playbooks that are part of the solution for Fortinet without issues? I am having several issues with all of them!!

Fortinet-FortiGate-ResponseOnBlockURL

Fortinet-FortiGate-ResponseOnBlockIP

Fortinet-FortiGate-IPEnrichment

If anyone has encountered and overcome issues creating these playbooks please let me know

Thanks

Rob

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
976 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 9,491 Reputation points Microsoft Employee
    2024-03-28T12:36:50.32+00:00

    Hard to response based on the info provided. I don't have an API key and ran into blockers setting up a test deployment. I was also unable to find the documentation mentioned in the instructions. You might be able to get addtional support from the vendor since they created the solution.

    Though generally you will likely need an Automation Rule to send incidents to the playbooks and only those with related entities will successfully trigger the responses.