Fortinet white logo
Fortinet white logo

EMS Administration Guide

Uploading signatures for FortiGuard Outbreak Alerts service

Uploading signatures for FortiGuard Outbreak Alerts service

You can use a security posture tagging rule as a predefined rule for FortiGuard outbreak alerts by uploading rule signatures.

To configure a security posture tagging rule as a predefined rule for outbreak alerts by uploading rule signatures:
  1. In EMS, go to Security Posture Tags > Security Posture Tagging Rules.
  2. Click Import Signatures.

  3. In the Import FortiGuard Outbreak Alert Signatures dialog, upload a JSON file. The JSON file should contain an array of alert objects, each with a tag name and array of signatures. Each signature should have the following properties: os (windows, mac, linux, ios, android), type (file, registry, process), and content. If the import succeeds, EMS displays a FortiGuard outbreak alert signatures imported successfully message. If the file is formatted incorrectly, EMS shows an Invalid JSON error.
  4. View tagged endpoints in Security Posture Tags > Security Posture Tag Monitor.

Uploading signatures for FortiGuard Outbreak Alerts service

Uploading signatures for FortiGuard Outbreak Alerts service

You can use a security posture tagging rule as a predefined rule for FortiGuard outbreak alerts by uploading rule signatures.

To configure a security posture tagging rule as a predefined rule for outbreak alerts by uploading rule signatures:
  1. In EMS, go to Security Posture Tags > Security Posture Tagging Rules.
  2. Click Import Signatures.

  3. In the Import FortiGuard Outbreak Alert Signatures dialog, upload a JSON file. The JSON file should contain an array of alert objects, each with a tag name and array of signatures. Each signature should have the following properties: os (windows, mac, linux, ios, android), type (file, registry, process), and content. If the import succeeds, EMS displays a FortiGuard outbreak alert signatures imported successfully message. If the file is formatted incorrectly, EMS shows an Invalid JSON error.
  4. View tagged endpoints in Security Posture Tags > Security Posture Tag Monitor.