Splunk Phantom

How to block incoming traffic (source ip at FW policy) with phantom check point/ fortinet apps?

stevenaung
New Member

Hi all,

I was testing out phanom to contain malicious IPs with my perimeter FWs.
The problem is that it only block as destination IP at FW and i didn't see any parameter to define whether I want to block as destination or source or both.
I believe FW API supports this functionality but somehow it is missing.
Any thoughts on this?

Labels (2)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!