Does anyone have any experience of the Fortigate active response - https://splunkbase.splunk.com/app/3444/
If so do you know if there is a new policy created each time a block is initated as a result of an alert or if it is a single policy and new IP's are appended to that policy.
If it is a new policy - how have you managed cleaning it up afterwards when the block is no longer required?