FortiGate Active Response Add-on For Splunk Enterprise
FortiGate Active Response Add-on For Splunk Enterprise
The Fortinet Active Response add-on defined an alert action, which will enable users to block traffic from/to a particular source IP, destination IP or a network user through FortiGate's RESTful API based on correlation search result. It leverages Adaptive Response Framework solution provided by Splunk Enterprise.