Fortinet white logo
Fortinet white logo

Overview

Overview

FortiSOAR is a platform designed to help organize records, actions, and workflows, allowing you to manage the entire lifecycle of a threat or breach within your organization. The SOAR Framework Solution Pack offers a comprehensive framework for creating security task workflows and establishing the groundwork for a Security Operations Center (SOC) to utilize the FortiSOAR platform for incident response and automation use cases as efficiently as possible. This framework's components can be modified and expanded upon by system administrators to suit their requirements.

This guide is intended to help new or experienced FortiSOAR administrators configure the system optimally using best practices, and intends to familiarize you with the application and start exploring some of the core capabilities offered by FortiSOAR. It also gives a general overview of how to deploy and set up FortiSOAR; for detailed step-by-step instructions, see the "Deployment Guide", and the "Administration Guide".

The guide focuses on setting up the 'Enterprise' flavor of FortiSOAR. For multi-tenant environments see the "Multi-Tenancy Support Guide", and for high availability see the "High Availability and Disaster Recovery support in FortiSOAR" chapter in the "Administration Guide".

Note

When administrators log into FortiSOAR for the first time, they are presented with a 'Setup Guide' that assists them in configuring FortiSOAR for optimal functioning. For more information, see the Setup Guide documentation.

The guide is divided into the following sections:

  • Deploy - Prepare your FortiSOAR system with the right hardware configuration, install FortiSOAR, and optimize your network and security settings for performance. For more information, see Deployment and initial configuration
  • Streamline - Set up the incident response platform based on your record flow and automation of tasks such as ingestion, enrichment, and mitigation. For more information, see Design your incident response platform
  • Accelerate - Leverage and customize various pre-defined playbooks and explore provided specialized Solution Packs. For more information, see Customize playbooks and solution packs .
  • Maintain - Enable monitoring of your FortiSOAR system to ensure availability and optimal performance. For more information, see Maintain your FortiSOAR system.

For detailed information on FortiSOAR, see the FortiSOAR product documentation and visit the FortiSOAR user community.

Overview

Overview

FortiSOAR is a platform designed to help organize records, actions, and workflows, allowing you to manage the entire lifecycle of a threat or breach within your organization. The SOAR Framework Solution Pack offers a comprehensive framework for creating security task workflows and establishing the groundwork for a Security Operations Center (SOC) to utilize the FortiSOAR platform for incident response and automation use cases as efficiently as possible. This framework's components can be modified and expanded upon by system administrators to suit their requirements.

This guide is intended to help new or experienced FortiSOAR administrators configure the system optimally using best practices, and intends to familiarize you with the application and start exploring some of the core capabilities offered by FortiSOAR. It also gives a general overview of how to deploy and set up FortiSOAR; for detailed step-by-step instructions, see the "Deployment Guide", and the "Administration Guide".

The guide focuses on setting up the 'Enterprise' flavor of FortiSOAR. For multi-tenant environments see the "Multi-Tenancy Support Guide", and for high availability see the "High Availability and Disaster Recovery support in FortiSOAR" chapter in the "Administration Guide".

Note

When administrators log into FortiSOAR for the first time, they are presented with a 'Setup Guide' that assists them in configuring FortiSOAR for optimal functioning. For more information, see the Setup Guide documentation.

The guide is divided into the following sections:

  • Deploy - Prepare your FortiSOAR system with the right hardware configuration, install FortiSOAR, and optimize your network and security settings for performance. For more information, see Deployment and initial configuration
  • Streamline - Set up the incident response platform based on your record flow and automation of tasks such as ingestion, enrichment, and mitigation. For more information, see Design your incident response platform
  • Accelerate - Leverage and customize various pre-defined playbooks and explore provided specialized Solution Packs. For more information, see Customize playbooks and solution packs .
  • Maintain - Enable monitoring of your FortiSOAR system to ensure availability and optimal performance. For more information, see Maintain your FortiSOAR system.

For detailed information on FortiSOAR, see the FortiSOAR product documentation and visit the FortiSOAR user community.