Fortinet white logo
Fortinet white logo

Product integration and support

Product integration and support

Integrations

The following table lists FortiNDR Cloud product integration and support information. Integration guides are available on the FortiNDR Cloud Integrations page.

Category

Integration

Supported Version/Notes

Deception

FortiDeceptor

Requires Automation Service

SIEM

CrowdStrike

Tested with Parser 1.0.2

FortiSIEM 7.1.0 or higher
Microsoft Sentinel Integration supported via API-based ingestion.
QRadar IBM QRadar SIEM version 7.3.3 or higher
Splunk Splunk Cloud versions: 9.3, 9.2, 9.1
SOAR Cortex-XSOAR Tested on: 6.6
FortiSOAR Tested on: 7.3.2-2150
Splunk SOAR

7.3.2-2150 or higher

EDR / Firewall

FortiEDR

Manager 6.2.0 or higher

Collector 5.2.0 or higher

FortiClientEMS

Requires Automation Service

FortiManager

7.4.2 or higher

FortiGate

7.4.2 or higher

CrowdStrike EDR

Requires latest Falcon EDR APIs

SentinelOne

Requires Automation Service

Intelligence Feeds

CrowdStrike Falcon Intel

License required

Fortinet Botnet IP List

Included with FortiNDR Cloud

Internet Scan Data B (Shodan)

Included with FortiNDR Cloud

Known Sinkholes

Included with FortiNDR Cloud

PhishTank

Included with FortiNDR Cloud

Proofpoint TAP

License required

Recorded Future connect

License required

Threat Connect

License required

Tor Nodes

Included with FortiNDR Cloud

URLHaus

Included with FortiNDR Cloud

Other

Endace 7.2.2 or higher

ERSPAN

Type II and Type III

Netskope

Integration via Cloud TAP Stitcher.

Netflow

NetFlow v5, v9, IPFIX and UDP/6343 (SFlow)

Zscaler

Integration supported through NSS for traffic and threat logs.

Fortinet Automation Service

The following table lists the current Fortinet Automation Service solution pack versions. For information about the Fortinet Automation Service, see the FortiNDR Cloud User Guide.

Solution Pack Version Connectors and Playbooks
1.0.0 FortiClientEMS, FortiEDR, FortiDeceptor
1.0.1 FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, Sentinel One

1.0.2

FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, FortiProxy, Sentinel One

Product integration and support

Product integration and support

Integrations

The following table lists FortiNDR Cloud product integration and support information. Integration guides are available on the FortiNDR Cloud Integrations page.

Category

Integration

Supported Version/Notes

Deception

FortiDeceptor

Requires Automation Service

SIEM

CrowdStrike

Tested with Parser 1.0.2

FortiSIEM 7.1.0 or higher
Microsoft Sentinel Integration supported via API-based ingestion.
QRadar IBM QRadar SIEM version 7.3.3 or higher
Splunk Splunk Cloud versions: 9.3, 9.2, 9.1
SOAR Cortex-XSOAR Tested on: 6.6
FortiSOAR Tested on: 7.3.2-2150
Splunk SOAR

7.3.2-2150 or higher

EDR / Firewall

FortiEDR

Manager 6.2.0 or higher

Collector 5.2.0 or higher

FortiClientEMS

Requires Automation Service

FortiManager

7.4.2 or higher

FortiGate

7.4.2 or higher

CrowdStrike EDR

Requires latest Falcon EDR APIs

SentinelOne

Requires Automation Service

Intelligence Feeds

CrowdStrike Falcon Intel

License required

Fortinet Botnet IP List

Included with FortiNDR Cloud

Internet Scan Data B (Shodan)

Included with FortiNDR Cloud

Known Sinkholes

Included with FortiNDR Cloud

PhishTank

Included with FortiNDR Cloud

Proofpoint TAP

License required

Recorded Future connect

License required

Threat Connect

License required

Tor Nodes

Included with FortiNDR Cloud

URLHaus

Included with FortiNDR Cloud

Other

Endace 7.2.2 or higher

ERSPAN

Type II and Type III

Netskope

Integration via Cloud TAP Stitcher.

Netflow

NetFlow v5, v9, IPFIX and UDP/6343 (SFlow)

Zscaler

Integration supported through NSS for traffic and threat logs.

Fortinet Automation Service

The following table lists the current Fortinet Automation Service solution pack versions. For information about the Fortinet Automation Service, see the FortiNDR Cloud User Guide.

Solution Pack Version Connectors and Playbooks
1.0.0 FortiClientEMS, FortiEDR, FortiDeceptor
1.0.1 FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, Sentinel One

1.0.2

FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, FortiProxy, Sentinel One