Actions for Fortinet FortiGate #
- Send Data to Fortinet FortiGate. Sends a custom set of Lucidum data to Fortinet FortiGate.
Use Cases #
Below are the possible use cases for these actions:
-
If you want to run Lucidum “headless”, you can send relevant data to Fortinet FortiGate on a regular schedule.
- You can send normalized, enriched Lucidum data to Fortinet FortiGate to be indexed, searched, and analyzed.
Prerequisites #
To execute Fortinet FortiGate actions, you must
Configure a Fortinet FortiGate API connection beforehand. The required parameters are described in the instructions for creating a Fortinet FortiGate connector in Lucidum https://lucidum.io/docs/microsoft-active-directory.
NOTE. The specified account should have read and write permissions.
Workflows #
- Creating a new Configuration and a new Action
- Cloning an Existing Action
- Creating a new Action from the Location Results page
- Editing a Configuration
- Editing an Action
- Viewing Information about an Action
Fortinet FortiGate Configuration #
To create a configuration for Fortinet FortiGate actions:
-
Configuration Name. Identifier for the Configuration. This name will appear in the Lucidum Action Center.
- Host. The IP address or hostname of the Fortigate firewall. For example, 10.2.290.29.
-
Port. Port for the Fortigate firewall. Default is 443.
-
Username. User name of a REST API administrator with read and write access to the Fortigate API. For details, see https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/399023/rest-api-administrator and https://community.fortinet.com/t5/FortiGate/Technical-Tip-About-REST-API/ta-p/195425.
-
Password. API Key for a REST API administrator with read and write access to the Fortigate API. For details, see https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/399023/rest-api-administrator and https://community.fortinet.com/t5/FortiGate/Technical-Tip-About-REST-API/ta-p/195425.
-
Max # of Records per Payload. The maximum number of records to send to Fortinet FortiGate in each action. The default value is “50”.
Create a New Action #
To create an action for Fortinet FortiGate, contact Lucidum customer care.