Fortinet white logo
Fortinet white logo

Configure Indicator Extraction

Configure Indicator Extraction

The SOAR Framework Solution Pack (SFSP) includes indicator extraction playbooks that are triggered automatically when an alert or incident is created. These playbooks extract indicators from alert or incident fields and enrich them using predefined enrichment playbooks based on the indicator type.

To optimize the extraction process, you can configure the indicator extraction logic to match specific alert or incident types, add custom indicator types, or include additional fields of interest in the playbook to capture more data beyond the default fields, etc.

You can also exclude certain indicators from enrichment by adding them to an exclusion list, which helps reduce false positives and improve overall efficiency.

For more information, see the Indicator Extraction Configuration widget.

Configure Indicator Extraction

Configure Indicator Extraction

The SOAR Framework Solution Pack (SFSP) includes indicator extraction playbooks that are triggered automatically when an alert or incident is created. These playbooks extract indicators from alert or incident fields and enrich them using predefined enrichment playbooks based on the indicator type.

To optimize the extraction process, you can configure the indicator extraction logic to match specific alert or incident types, add custom indicator types, or include additional fields of interest in the playbook to capture more data beyond the default fields, etc.

You can also exclude certain indicators from enrichment by adding them to an exclusion list, which helps reduce false positives and improve overall efficiency.

For more information, see the Indicator Extraction Configuration widget.