SIEM integration
Automate Fortinet FortiSIEM with plain language
Read FortiSIEM incidents, monitored devices and rules, and push an external event when VernacSecure SuperBot™ observes something worth correlating.
What you can do
FortiSIEM — Supervisor REST API
- List incidents and their severity
- Read the CMDB device inventory
- Read correlation rules
- Forward a VernacSecure SuperBot™ event
Connection: basic authentication against https://fortisiem.example.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Fortinet FortiSIEM”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch incidents — Lists incidents raised by FortiSIEM.
- Fetch CMDB devices — Lists monitored devices from the CMDB.
- Fetch rules — Lists correlation rules.
Write actions
- Forward event — Sends an external event into FortiSIEM.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Exabeam Security Operations · Google Security Operations (Chronicle)