Podcast
Questions and Answers
Which feature of FortiSOAR facilitates data ingestion from external SIEM solutions and other third-party sources?
Which feature of FortiSOAR facilitates data ingestion from external SIEM solutions and other third-party sources?
What can you do with the data ingestion wizard in FortiSOAR?
What can you do with the data ingestion wizard in FortiSOAR?
Which mode of data ingestion in FortiSOAR is triggered by a notification service?
Which mode of data ingestion in FortiSOAR is triggered by a notification service?
How often are the fetch playbooks scheduled to run by default in FortiSOAR?
How often are the fetch playbooks scheduled to run by default in FortiSOAR?
Signup and view all the answers
What does the app push feature in FortiSOAR allow you to do?
What does the app push feature in FortiSOAR allow you to do?
Signup and view all the answers
What does the data ingestion wizard in FortiSOAR fetch from the source?
What does the data ingestion wizard in FortiSOAR fetch from the source?
Signup and view all the answers
What does the notification service in FortiSOAR trigger?
What does the notification service in FortiSOAR trigger?
Signup and view all the answers
What does the fetch API in FortiSOAR allow you to do?
What does the fetch API in FortiSOAR allow you to do?
Signup and view all the answers
What does the schedule-based mode of data ingestion in FortiSOAR use?
What does the schedule-based mode of data ingestion in FortiSOAR use?
Signup and view all the answers
What does the fetch playbook in FortiSOAR allow you to do?
What does the fetch playbook in FortiSOAR allow you to do?
Signup and view all the answers
Which mode of data ingestion uses fetch APIs of the integration?
Which mode of data ingestion uses fetch APIs of the integration?
Signup and view all the answers
Which mode of data ingestion requires the installation of a FortiSOAR add-on on the server side?
Which mode of data ingestion requires the installation of a FortiSOAR add-on on the server side?
Signup and view all the answers
Which mode of data ingestion requires configuration of a user password or appliance-based authentication in FortiSOAR?
Which mode of data ingestion requires configuration of a user password or appliance-based authentication in FortiSOAR?
Signup and view all the answers
What happens if both notification-based and schedule-based ingestion are configured for the same source?
What happens if both notification-based and schedule-based ingestion are configured for the same source?
Signup and view all the answers
What type of connectors have a Configure Data Ingestion tab?
What type of connectors have a Configure Data Ingestion tab?
Signup and view all the answers
What tags are included in each playbook that contributes to data ingestion?
What tags are included in each playbook that contributes to data ingestion?
Signup and view all the answers
What does the Fetch Playbook do?
What does the Fetch Playbook do?
Signup and view all the answers
What information does the Connectors page provide about data ingestion connectors?
What information does the Connectors page provide about data ingestion connectors?
Signup and view all the answers
What should be done if you decide to use the sample playbooks in your environment?
What should be done if you decide to use the sample playbooks in your environment?
Signup and view all the answers
What can be done with sample playbooks from data ingestion connectors like Fortinet FortiSIEM?
What can be done with sample playbooks from data ingestion connectors like Fortinet FortiSIEM?
Signup and view all the answers
Study Notes
FortiSOAR Data Ingestion
Data Ingestion Features
- The Data Ingestion Wizard facilitates data ingestion from external SIEM solutions and other third-party sources.
- The App Push feature allows you to push data from external sources to FortiSOAR.
- The Fetch API allows you to fetch data from external sources.
Data Ingestion Modes
- There are two modes of data ingestion: Notification-based and Schedule-based.
- Notification-based mode is triggered by a notification service.
- Schedule-based mode uses a schedule to fetch data from external sources.
- Fetch playbooks are scheduled to run by default every 5 minutes.
Data Ingestion Wizard
- The Data Ingestion Wizard fetches data from the source using the Fetch API.
- The wizard configures the data ingestion process.
Fetch Playbook
- The Fetch Playbook allows you to fetch data from external sources.
- The playbook is used to contribute to data ingestion.
Connectors
- Some connectors have a Configure Data Ingestion tab.
- The Connectors page provides information about data ingestion connectors.
Sample Playbooks
- Sample playbooks from data ingestion connectors like Fortinet FortiSIEM can be used as a starting point.
- If you decide to use the sample playbooks, you should customize them to fit your environment.
Conflict Resolution
- If both notification-based and schedule-based ingestion are configured for the same source, the notification-based ingestion takes precedence.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Description
Test your knowledge on data ingestion with FortiSOAR! Learn about the dedicated data ingestion wizard, scheduling periodic data ingestion, mapping fields between FortiSOAR and data sources, defining content pulling frequency, and using sample playbooks. Challenge yourself and become an expert in data ingestion with FortiSOAR!