Fortinet white logo
Fortinet white logo

Administration Guide

Security Automation Service objects

Security Automation Service objects

The FortiAnalyzer Security Automation Service includes support for the RHSP FortiGuard package which is used to share updated reports, event handlers, SIEM parsers, and playbooks as content packages. RHSP FortiGuard package objects are only applied with a valid Security Automation Service license.

You can find the Security Automation Service objects received as part of the FortiGuard packages in the following places in FortiAnalyzer:

Reports:

Reports included in the package are stored on the global level, and are displayed in the global Security Automation Reports folder. The global folder and global reports are identified with the system theme's color applied to the icon. Reports delivered by the package display FortiGuard in the Origin column.

Event handlers:

Basic event handlers delivered by the package are displayed in Incidents & Events > Handlers > Basic Handlers. Correlation event handlers are displayed in Incidents & Events > Handlers > Correlation Handlers.

SIEM parsers:

SIEM parsers delivered by the package are displayed in Incidents & Events > Log Parsers, and display FortiGuard in the Origin column.

Playbooks:

Playbooks delivered by the package are displayed in Fabric View > Automation > Playbook.

Security Automation Service objects

Security Automation Service objects

The FortiAnalyzer Security Automation Service includes support for the RHSP FortiGuard package which is used to share updated reports, event handlers, SIEM parsers, and playbooks as content packages. RHSP FortiGuard package objects are only applied with a valid Security Automation Service license.

You can find the Security Automation Service objects received as part of the FortiGuard packages in the following places in FortiAnalyzer:

Reports:

Reports included in the package are stored on the global level, and are displayed in the global Security Automation Reports folder. The global folder and global reports are identified with the system theme's color applied to the icon. Reports delivered by the package display FortiGuard in the Origin column.

Event handlers:

Basic event handlers delivered by the package are displayed in Incidents & Events > Handlers > Basic Handlers. Correlation event handlers are displayed in Incidents & Events > Handlers > Correlation Handlers.

SIEM parsers:

SIEM parsers delivered by the package are displayed in Incidents & Events > Log Parsers, and display FortiGuard in the Origin column.

Playbooks:

Playbooks delivered by the package are displayed in Fabric View > Automation > Playbook.