Fortinet white logo
Fortinet white logo
2024.10.0

Overview

Overview

The FortiNDR Cloud App for Splunk allows administrators to incorporate the network telemetry data collected and analyzed by FortiNDR Cloud into their Splunk deployment.

This app polls FortiNDR Cloud APIs to import detections events into Splunk. In addition, Suricata and Observation events may be imported via Metastream S3 import.

After the initial import, the app will periodically poll FortiNDR Cloud at a specified interval for new events to import. Additional information can also be imported for specified entities, such as Passive DNS records, DHCP records, and virus total.

Note

AWS access is required to poll raw events from AWS S3 Buckets.

See FortiNDR Cloud Events for information on how to configure a FortiNDR Cloud Events input.

Overview

Overview

The FortiNDR Cloud App for Splunk allows administrators to incorporate the network telemetry data collected and analyzed by FortiNDR Cloud into their Splunk deployment.

This app polls FortiNDR Cloud APIs to import detections events into Splunk. In addition, Suricata and Observation events may be imported via Metastream S3 import.

After the initial import, the app will periodically poll FortiNDR Cloud at a specified interval for new events to import. Additional information can also be imported for specified entities, such as Passive DNS records, DHCP records, and virus total.

Note

AWS access is required to poll raw events from AWS S3 Buckets.

See FortiNDR Cloud Events for information on how to configure a FortiNDR Cloud Events input.