Deployment Plan
The high-level deployment plan is as follows:
-
FortiSIEM – Install FortiSIEM Agents and enable UEBA where licensed. Specific steps to deploy and enable can be found in the Windows Agent Installation Guide.
-
FortiSIEM - Define IP watchlist.
-
FortiSIEM - Import the custom rules.
-
FortiSIEM - Customize the rules to reference the watchlists.
-
FortiGate - Configure the FortiGate to collect the IPs from the Fabric watchlists.
-
FortiGate – Configure use case for FortiGate consumption of the IP Address Threat Feed.