Overview
The FortiNDR Cloud solution for Microsoft Sentinel allows users to incorporate the network telemetry data collected and analyzed by FortiNDR Cloud into their Sentinel deployment.
The solution provides two types of inputs: Detections and Events (includes Suricata and Observations). Events and associated metadata can be retrieved by the data connector using FortiNDR Cloud API and stored in Azure Log Analytics workspaces.
The solution also includes Parsers and Workbooks to help organizations to drive deeper and more efficient investigations.
Requirements
The following are required for setting up the FortiNDR Cloud Solution on Microsoft Sentinel:
- Microsoft Azure
- FortiNDR Cloud Portal