Configuring Fortinet FortiNDR Cloud for Microsoft Sentinel
Prepare the Microsoft Sentinel Environment
You can skip the following steps if Resource groups, Log Analytics workspaces and Microsoft Sentinel are already set up. |
1. Create Resource groups for the FortiNDR Cloud integration
- In Microsoft Azure, search for Resource groups, and click it.
- Click Create.
- Follow the steps in the wizard to create a new Resource group.
2. Set up Log Analytics workspaces for FortiNDR Cloud Sentinel
- In Microsoft Azure, search for Log Analytics workspaces, and click it.
- Click Create. The workspace Create Log Analytics page opens.
- From the Subscription dropdown, select the newly created Resource group, and use the wizard to create a new Log Analytics workspace.
3. Set up Microsoft Sentinel
- In Microsoft Azure, search for Sentinel, and click it.
- Click Create. The Add Microsoft Sentinel to a workspace page opens.
- Search for and then select the Log Analytics workspace to add Sentinel, and then click Add.
Microsoft Sentinel Integration
To integrate FortiNDR Cloud with Microsoft Sentinel:
- In Microsoft Marketplace, go to the FortiNDR Cloud Sentinel Page.
- Select a plan and click Create. The Create FortiNDR Cloud Sentinel page opens.
- From the dropdowns, select a Subscription, Resource group, and Log Analytics workspace, and then use the wizard to create the Integration.