config system fortiguard ioc
Use this command to configure FortiNDR to query IOC (Indicator of Compromise) data from a custom FortiGuard server instead of the default.
Syntax
config system fortiguard ioc set ioc-override-server-address <ovr_svr> set ioc-override-server-port <port_num> set ioc-override-server-status <enable/disable> end
|
Variable |
Description |
Default |
|---|---|---|
|
ioc-override-server-address |
Specifies the override IP address of the FortiGuard IOC server. The default is 0.0.0.0
|
0.0.0.0 |
|
ioc-override-server-port |
Port number to ioc override fortiguard server. The default is 443 |
44 |
|
ioc-override-server-status {enable | disable} |
When enabled, FortiNDR will send IOC
queries to the override server specified in |
disable |