Unable to connect from FortiSOAR to Splunk cloud instance. Healthcheck in FortiSOAR is showing Disconnected, even though I have entered the correct credentials and port.
You need to ensure that the FortiSOAR's IP address is whitelisted in Splunkcloud as it is mostly geofenced for initiating connections via the API. Also, the user that you have created should have enough access to do what you are trying to accomplish by having appropriate role assigned to it in Splunk cloud.
Hope this helps.
Hi, thank you gor the reply. How do I check the if the IP is white listed? The FortiSoar is hosted in AWS.
Are you using Victoria experience or classic experience in Splunkcloud.
If you are using classic experience, please file a Splunk support case to check and get SOAR's IP address whitelisted.
If you are using Victoria experience, you can go to Settings -> Server Settings -> IP allow list for doing the same. Please note that this requires a user with sc_admin role assigned to it.