Security Operations Center-as-a-Service (SOCaaS)
Fortinet Security Operations Center-as-a-Service (SOCaaS) offers a cloud-based security monitoring service that analyzes security events generated from your FortiWeb device, performs alert triage, and escalates confirmed threat notifications. Its key services include:
-
Real-time web application and API security monitoring
-
Clear Call to Action on detected Web Attacks
-
Noise reduction of False Positives and Information alerts
-
Weekly FortiWeb executive and threat protection report
Contact Fortinet sales team to purchase the Fortinet SOCaaS service license.
The following section outlines the steps to send FortiWeb attack logs to the SOCaaS team for security services.
Step 1 Enable Threat Analytics on FortiWeb
Step 2 Configure exporting attack logs to FortiAppSec Cloud
Step 3 Create an IAM user for the SOCaaS team
Step 4 Wait for the SOCaaS team to complete configuration
Step 5 Onboard your application on SOCaaS
Step 1 Enable Threat Analytics on FortiWeb
When FortiWeb is deployed within a private network, it can be challenging for the SOCaaS service to retrieve attack logs and perform security services effectively.
To address this, FortiWeb’s Threat Analytics feature provides a solution by exporting attack logs to a publicly accessible location. When Threat Analytics is enabled on FortiWeb, attack logs are exported to FortiAppSec Cloud. The SOCaaS service can then access these logs from FortiAppSec Cloud to carry out the necessary security operations.
Perform the following steps to enable Threat Analytics on FortiWeb:
- Contact Sales team to purchase a license with the Threat Analytics service, then register the license on Support site: https://support.fortinet.com
- Log in to FortiWeb.
- Check the status of Threat Analytics in the Licenses widget in Dashboard > Status. It should be displayed as Valid.

- In the System Information Widget in Dashboard > Status, click Enable Threat Analytics, then click OK in the pop-up window.

Step 2 Configure exporting attack logs to FortiAppSec Cloud
- In FortiWeb, turn on Enable Attack Log in Log&Report > Log Config > Other Log Settings.
- Go to Dashboard > Status, click Add Widget, then select Threat Analytics in the System section. The Threat Analytics widget will be displayed on the Status page. You can view whether FortiWeb is successfully connected with FortiWeb Cloud and whether the attack logs are being forwarded.

- Wait for FortiWeb to generate attack logs.
- Log in to FortiAppSec Cloud with the account you used when registering your license on Fortinet Support site.
- Navigate to Threat Analytics menu. Check the attack logs are displayed in FortiAppSec Cloud.
Step 3 Create an IAM user for the SOCaaS team
Step 3.1 Set permission profile for SOCaaS IAM
- Log in to FortiCloud: https://support.fortinet.com/welcome/#/
- Select service from top menu and click “IAM” as following:

- You will see the following page:

- Select Permission Profiles and click Add New:

- Enter permission profile name and optional description and click Add Portal.

- Check FortiAppSec Cloud box and click Add.

- Set General and Threat Analytics to Read & Write. Click Submit.

- A new permission profile is added successfully.

Step 3.2 Create a user for SOCaaS team
- Select Users, click Add New, then then click IAM User.

- Input the Username, Full Name, Email and Phone, then click Next. For the email address, use “
socaas-noreply@fortinet-us.com”. - select a Asset Folder. then select the permission profile created in the last step. Click Next.

- Click Confirm, the IAM user is created successfully.
- Click Generate Password. The link will be displayed and click Copy Reset Link to copy the link.

Step 3.3 Share the password link with SOCaaS team
-
Copy and share the Generate password link with the SOCaaSTeam over email
socaas@fortinet.com. SOCaaS team will set its own password. - Verify TFA setting and make sure it is set to Email, not FortiToken. As shown below, you need to switch on the Email button.
Step 4 Wait for the SOCaaS team to complete configuration
When onboarding FortiWeb to SOCaaS, the process typically involves a waiting period for configuration and service preparation.
Once the configurations are complete, the SOCaaS team will contact you via email to confirm that the SOCaaS service for your FortiWeb device is ready.
Step 5 Onboard your application on SOCaaS
The final step is to onboard your application on Fortinet SOCaaS. Refer to the following article from Fortinet SOCaaS: Onboarding FortiWeb or FortiAppSec Cloud.
To check your SOCaaS service license status in FortiWeb:
-
In FortiWeb, go to Dashboard > Status and locate the Licenses widget to view the SOCaaS service license status.
Hovering over the SOCaaS license displays its status and expiration date.
-
Optionally, click the SOCaaS license entry to redirect to System > Config > FortiGuard, where you can review detailed license information and subscription details.