Skip to content

Commit 99fe7fb

Browse files
3.1.0 Changes (#277)
- Release notes - Indicator extraction doc - Icons and screenshots - upgrade doc with added sections - - Moving from Global Variables to Key Store Record - Editing Extraction Playbooks - An Example - Retrieving Exclusion List
1 parent 1828656 commit 99fe7fb

21 files changed

+794
-3264
lines changed

README.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
- **Version**: 3.1.0
44
- **Certified**: Yes
55
- **Publisher**: Fortinet
6-
- **Compatible Version**: FortiSOAR v7.6.0 and later
6+
- **Compatible Version**: FortiSOAR v7.6.1 and later
77
- [Release Notes](./release_notes.md)
88

99
# Overview
@@ -66,7 +66,6 @@ The following diagram helps better understand the overall process and the subseq
6666

6767
A **War Room** in this scenario brings together all the above teams and helps devise a more intuitive plan of action.
6868

69-
<!-- - **Incident Response** - These playbooks help plan a response to an incident such as a malware attack. -->
7069

7170
## Additional Resources
7271

@@ -80,6 +79,8 @@ The following diagram helps better understand the overall process and the subseq
8079

8180
- [Extending Default Indicator Extraction Process](./docs/extending-default-indicator-extraction-process.md)
8281

82+
- [Excluding Extracted Indicators from Enrichment](./docs/extending-default-indicator-extraction-process.md#excluding-extracted-indicators-from-enrichment)
83+
<!-- Pre -->
8384
- [Extending Default Indicator Enrichment Process](./docs/extending-default-indicator-enrichment-process.md)
8485

8586
- [Building Investigation/Response Playbook](./docs/building-investigation-response-playbook.md)
@@ -88,7 +89,6 @@ The following diagram helps better understand the overall process and the subseq
8889

8990
- [Setting up Communications Tracking for Custom Modules](./docs/setting-up-comms-module.md)
9091

91-
- [Excluding Extracted Indicators from Enrichment](./docs/extending-default-indicator-extraction-process.md#excluding-extracted-indicators-from-enrichment)
9292

9393
## Next Steps
9494

docs/configuring-alert-ingestion-process.md

Lines changed: 15 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33

44
# Configuring Alert Ingestion Process
55

6-
Alert Ingestion is a process that periodically pulls actionable data from sources such as SIEM, EDR, and even email inboxes. For example, to respond to use cases involving suspicous emails, you would configure ingestion of emails from email providers like Exchange or GMail.
6+
Alert Ingestion is a process that periodically pulls actionable data from sources such as SIEM, EDR, and even email inboxes. For example, to respond to use cases involving suspicious emails, you would configure ingestion of emails from email providers like Exchange or GMail.
77

88
The **Data Ingestion** page displays all the connectors that are installed and can be configured for alert ingestion using the **Data Ingestion Wizard**.
99

@@ -13,15 +13,21 @@ To view the **Data Ingestion** page, log on to FortiSOAR. On the left navigation
1313

1414
1. To configure a connector for data ingestion, refer to the document [Configuring a connector in FortiSOAR](https://docs.fortinet.com/document/fortisoar/0.0.0/configuring-a-connector/1/configuring-a-connector#Configuring_a_connector_in_FortiSOAR_). Following connectors are installed, by default, with SOAR Framework Solution Pack:
1515

16-
- **Exchange** - To configure the Exchange connector for data ingestion, refer to the document [Configure Data Ingestion in Exchange](https://docs.fortinet.com/document/fortisoar/3.4.4/exchange/148/exchange-v3-4-4#Configure_Data_Ingestion).
17-
- **Fortinet FortiEDR** - To configure the Fortinet FortiEDR connector for data ingestion, refer to the document [Configure Data Ingestion in Fortinet FortiEDR](https://docs.fortinet.com/document/fortisoar/1.3.0/fortinet-fortiedr/161/fortinet-fortiedr-v1-3-0#Configure_Data_Ingestion).
18-
- **Fortinet FortiSIEM** - To configure the Fortinet FortiSIEM connector for data ingestion, refer to the document [Configure Data Ingestion in Fortinet FortiSIEM](https://docs.fortinet.com/document/fortisoar/4.3.1/fortinet-fortisiem/222/fortinet-fortisiem-v4-3-1#Configure_Data_Ingestion).
19-
- **IMAP** - To configure the IMAP connector for data ingestion, refer to the document [Configure Data Ingestion in IMAP](https://docs.fortinet.com/document/fortisoar/0.0.0/fortisoar-built-in-connectors/1/fortisoar-built-in-connectors#IMAP).
20-
There are multiple connectors each with separate instructions to configure data ingestion. To search for and know more, refer to [FortiSOAR Connectors](https://docs.fortinet.com/fortisoar/connectors).
21-
2. The **Data Ingestion Wizard** maps the incoming data (from source) to target field in the [Alert Schema](./extending-default-alert-schema.md). During the mapping process, you might find that you need to add some fields that are not present. To add new fields, refer to [Extending Default Alert Schema](./extending-default-alert-schema.md).
22-
> **IMPORTANT**: This is a key step to ensure correct mapping into alert schema, which subsequently becomes a part of the indicator extraction process.
16+
- **Exchange** - To configure the Exchange connector for data ingestion, refer to the document [Configure Data Ingestion in Exchange](https://docs.fortinet.com/document/fortisoar/3.4.4/exchange/148/exchange-v3-4-4#Configure_Data_Ingestion).
17+
18+
- **Fortinet FortiEDR** - To configure the Fortinet FortiEDR connector for data ingestion, refer to the document [Configure Data Ingestion in Fortinet FortiEDR](https://docs.fortinet.com/document/fortisoar/1.3.0/fortinet-fortiedr/161/fortinet-fortiedr-v1-3-0#Configure_Data_Ingestion).
19+
20+
There are multiple other connectors each with instructions to configure data ingestion. To search for and know more, refer to [FortiSOAR Connectors](https://docs. fortinet.com/fortisoar/connectors).
21+
22+
2. The **Data Ingestion Wizard** maps the incoming data (from source) to target field in the [Alert Schema](./extending-default-alert-schema.md). During the mapping process, you might need to add some fields that are not present; to add new fields, refer to [Extending Default Alert Schema](./extending-default-alert-schema.md).
23+
24+
>[!Important]
25+
>This is a key step to ensure correct mapping into alert schema, which subsequently becomes a part of the indicator extraction process.
26+
2327
3. Use the **Scheduling** screen, in the **Data Ingestion Wizard**, to configure schedule-based ingestion.
24-
> **NOTE**: Some connectors, like the **Exchange** connector, support **Email Notification Service**. This service sets up a listener that instantly notifies FortiSOAR when a new email arrives in the mailbox.
28+
29+
> [!Note]
30+
> Some connectors, like the **Exchange** connector, support **Email Notification Service**. This service sets up a listener that instantly notifies FortiSOAR when a new email arrives in the targeted mailbox.
2531
2632
After the configuration is complete, the system is ready to ingest data and as per the defined mapping, create alerts in FortiSOAR.
2733

0 commit comments

Comments
 (0)