Product integration and support
Integrations
The following table lists FortiNDR Cloud product integration and support information. Integration guides are available on the FortiNDR Cloud Integrations page.
|
Category |
Integration |
Supported Version/Notes |
|---|---|---|
|
Deception |
FortiDeceptor |
Requires Automation Service |
| SIEM |
Tested with Parser 1.0.2 |
|
| FortiSIEM | 7.1.0 or higher | |
| Microsoft Sentinel | Integration supported via API-based ingestion. | |
| QRadar | IBM QRadar SIEM version 7.3.3 or higher | |
| Splunk | Splunk Cloud versions: 9.3, 9.2, 9.1 | |
| SOAR | Cortex-XSOAR | Tested on: 6.6 |
| FortiSOAR | Tested on: 7.3.2-2150 | |
| Splunk SOAR |
7.3.2-2150 or higher |
|
|
EDR / Firewall |
Manager 6.2.0 or higher Collector 5.2.0 or higher |
|
|
|
FortiClientEMS |
Requires Automation Service |
|
|
7.4.2 or higher | |
|
|
FortiGate |
7.4.2 or higher |
|
|
CrowdStrike EDR |
Requires latest Falcon EDR APIs |
|
|
SentinelOne |
Requires Automation Service |
|
Intelligence Feeds |
License required | |
|
|
Fortinet Botnet IP List |
Included with FortiNDR Cloud |
|
|
Internet Scan Data B (Shodan) |
Included with FortiNDR Cloud |
|
|
Known Sinkholes |
Included with FortiNDR Cloud |
|
|
PhishTank |
Included with FortiNDR Cloud |
|
|
License required | |
|
|
License required | |
|
|
License required | |
|
|
Tor Nodes |
Included with FortiNDR Cloud |
|
|
URLHaus |
Included with FortiNDR Cloud |
|
Other |
Endace | 7.2.2 or higher |
|
|
ERSPAN |
Type II and Type III |
|
|
Netskope |
Integration via Cloud TAP Stitcher. |
|
|
Netflow |
NetFlow v5, v9, IPFIX and UDP/6343 (SFlow) |
|
|
Zscaler |
Integration supported through NSS for traffic and threat logs. |
Fortinet Automation Service
The following table lists the current Fortinet Automation Service solution pack versions. For information about the Fortinet Automation Service, see the FortiNDR Cloud User Guide.
| Solution Pack Version | Connectors and Playbooks |
|---|---|
| 1.0.0 | FortiClientEMS, FortiEDR, FortiDeceptor |
| 1.0.1 | FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, Sentinel One |
|
1.0.2 |
FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, FortiProxy, Sentinel One |