Connectors
...
Types of fortinet Configuratio...
FortiSIEM Get Incidents (By Time), Component
3 min
created fortisiem get incidents component, allowing us to pull incidents based on the defined “time front” and “time to” input parameters the component has integrated with soc solutions bundle’s component named “execute process bulk alerts“, which automates the process of ti enrichment and case record creation the creation of the component was referencing elasticsecurity get signals component note the component is created from tp24 2 8, with fortisiem v7 connector version 1 1 1 blue book instructions to deploy the component 1\ download this component and upload to the turbine instance fortisiem v7 get incidents ssp 2\ import ssp via turbine console > applications and applets > + sign at the top right corner > upload the file in \[1] 3\ upon import, you shall see the list of asset / component / connector, choose the following and import ‘fortisiem v7’ asset ‘fortisiem v7 get incidents’ component 'at bulk ingest alerts, fortisiem v7' playbook 4\ update asset details accordingly, url, username and password 5\ go to playbook named “at bulk ingest alerts, fortisiem v7“, configure action name ‘get time’, and set your desired ‘time from’ / ‘time to’ accordingly reference screenshots playbook test result 1 entry playbook ‘at bulk ingest alerts, fortisiem v7’, and component’s result of ‘fortisiem v7 get incidents’ fortisiem v7 get incidents action setting result of execute process bulk alerts case record creation using fortisiem incident