Connector Validation Test Case Report: Fortinet FortiSIEM v5.2.1


Failed Test Cases:


Test CaseResultStatus
Action Name is in Camel Case
Action NameCamel Case

List Incidents

True

Get Incident Details

True

Update Incident

True

Comment Incident

True

Clear Incident With Reason

True

Get Events For Incident

True

Search Events

True

Get Event Details

True

Get All Devices

True

Get All Devices For Specified IP Address Range

True

Get Device Information

True

List Monitored Devices and Attributes

True

List Monitored Organizations

True

Get Organization Details

True

Run Advanced Search Query

True

Get Event Attributes

True

Get Events Data By Query ID

True

Create Watch List

True

Get Watch Lists

True

Get Watch List Entries Count

True

Get Watch List Entry

True

Add Watch List Entries to Watch List

False

Update Watch List Entry

True

Delete Watch List Entry

True

Delete Watch List

True

Create Lookup Table

True

Get All Lookup Table

True

Delete Lookup Table

True

Import Lookup Table Data

True

Check Import Task Status

True

Get Lookup Table Data

True

Update Lookup Table Data

True

Delete Lookup Table Data

True

Get IP Context

True

Get Host Context

True

Get User Context

True

Fail

Playbook Names in Camel Case
PlayBooks NameCamel Case

Run Advanced Search Query

True

Get Incident Details

True

Get Watch List Entry

True

Delete Watch List Entry

True

Get Watch List Entries Count

True

Clear Incident With Reason

True

Delete Lookup Table

True

Create Lookup Table

True

Get Host Context

True

Get Organization Details

True

Search Events

True

Get User Context

True

List Monitored Devices and Attributes

True

Get Event Details

True

Get All Devices For Specified IP Address Range

True

Delete Lookup Table Data

True

Get Watch Lists

True

> FortiSIEM > Fetch

True

FortiSIEM > Ingest

True

Get Device Information

True

Get All Devices

True

List Monitored Organizations

True

Comment Incident

True

Update Lookup Table Data

True

>> FortiSIEM > Fetch Associated events for Incident

False

Add Watch List Entries to Watch List

False

Update Watch List Entry

True

Get Lookup Table Data

True

Update Incident

True

Get Event Attributes

True

Import Lookup Table Data

True

Get Events Data By Query ID

True

Delete Watch List

True

Get Events For Incident

True

Create Watch List

True

List Incidents

True

Get IP Context

True

Check Import Task Status

True

Get All Lookup Table

True

Fail




Test Case Execution Summary:


Test CaseResultStatus
Check Description is non empty
Action NameDescriptionDescription Available

List Incidents

Retrieves a list and details of incidents from the Fortinet FortiSIEM server based on the time range, and other filter criteria you have specified. NOTE: The FortiSIEM API does not support filtering incidents in the "List Incident" action based on sub-categories.

True

Get Incident Details

Retrieves details of an incident from the Fortinet FortiSIEM server based on the incident IDs you have specified.

True

Update Incident

Updates the attributes of a specific incident on the Fortinet FortiSIEM server based on the incident ID and other input parameters you have specified.

True

Comment Incident

Adds a comment to a specific incident on the Fortinet FortiSIEM server based on the incident ID you have specified.

True

Clear Incident With Reason

Clears an incident with the reason you have specified on the Fortinet FortiSIEM server based on the incident ID you have specified.

True

Get Events For Incident

Retrieves all associated events for a specified incident from the Fortinet FortiSIEM server, based on the incident ID and other input parameters you have specified.

True

Search Events

Searches for events in the Fortinet FortiSIEM server based on search attributes and other input parameters you have specified.

True

Get Event Details

Retrieves details of a specific event from the Fortinet FortiSIEM server based on the event ID you have specified and optionally the date range you have specified.

True

Get All Devices

Retrieves a short description for all devices that are configured on the Fortinet FortiSIEM server.

True

Get All Devices For Specified IP Address Range

Retrieves a short description for devices that are configured on the Fortinet FortiSIEM server, based on the IP address range that you have specified.

True

Get Device Information

Retrieves details of a specific device that is configured on the Fortinet FortiSIEM server, based on the Device IP that you have specified.

True

List Monitored Devices and Attributes

Retrieves a list and attributes of all monitored devices that are configured on the Fortinet FortiSIEM server.

True

List Monitored Organizations

Retrieves a list and details of all monitored organizations that are configured on the Fortinet FortiSIEM server.

True

Get Organization Details

Retrieves the details of a specific organization from the Fortinet FortiSIEM server based on the organization ID that you have specified.

True

Run Advanced Search Query

Runs an advanced search query on the Fortinet FortiSIEM server, based on the search conditions and other input parameters you have specified.

True

Get Event Attributes

Retrieves all event attributes from the Fortinet FortiSIEM server.

True

Get Events Data By Query ID

Retrieves data for events or incidents from the Fortinet FortiSIEM server based on the executed query ID you have specified.

True

Create Watch List

Creates a watch list in the FortiSIEM database. A watch list can contain one or more watch list entries.

True

Get Watch Lists

Retrieves details for all watch lists or for specific watch lists based on input parameters you have specified.

True

Get Watch List Entries Count

Returns the count of all watch list entries from all watch lists in Fortinet FortiSIEM.

True

Get Watch List Entry

Retrieves the specific watch list entry from Fortinet FortiSIEM based on the watch list entry ID you have specified.

True

Add Watch List Entries to Watch List

Adds watch list entries to one or more watch lists based on watch list ID and other input parameters you have specified.

True

Update Watch List Entry

Updates a watch list entry in the FortiSIEM database based on the watch list entry ID and other input parameters you have provided.

True

Delete Watch List Entry

Deletes watch list entries from the FortiSIEM database based on the ID of the watch list entries you have specified.

True

Delete Watch List

Deletes watch lists from the FortiSIEM database based on the ID of the watch lists you have specified.

True

Create Lookup Table

Creates the definition of a lookup table in the FortiSIEM server based on the name, column list, and other input parameters you have specified.

True

Get All Lookup Table

Retrieves the list of all lookupTable definitions from the FortiSIEM server based on the input parameters you have specified.

True

Delete Lookup Table

Deletes the lookupTable definition from the FortiSIEM server based on the lookup table ID you have specified.

True

Import Lookup Table Data

Imports the data of a specific CSV file in FortiSOAR to a specific lookup table in FortiSIEM based on the File/Attachment IRI, lookup table ID, and other input parameters you have specified.

True

Check Import Task Status

Checks the status of the import lookup table data task in FortiSIEM based on the lookup table ID and task ID you have specified.

True

Get Lookup Table Data

Retrieves items of the specified lookup table from FortiSIEM based on the lookup table ID and other input parameters you have specified.

True

Update Lookup Table Data

Updates items of a specified lookup table based on the lookup table ID, key, column data, and other input parameters you have specified.

True

Delete Lookup Table Data

Delete items of the specified lookup table in FortiSIEM based on the lookup table ID and primary keys you have specified.

True

Get IP Context

Retrieves the contextual data of the specified IP such as hostname, device type, location, device properties and known device information.

True

Get Host Context

Retrieves the contextual data of the specified hostname such as device type, and domain lookup information if an FQDN is supplied.

True

Get User Context

Retrieves the contextual data of the specified user such as known groups, location data, and top event types associated with this user account.

True

Pass
Action Description Non Camel Case
Action NameDescriptionCamel Case

List Incidents

Retrieves a list and details of incidents from the Fortinet FortiSIEM server based on the time range, and other filter criteria you have specified. NOTE: The FortiSIEM API does not support filtering incidents in the "List Incident" action based on sub-categories.

True

Get Incident Details

Retrieves details of an incident from the Fortinet FortiSIEM server based on the incident IDs you have specified.

True

Update Incident

Updates the attributes of a specific incident on the Fortinet FortiSIEM server based on the incident ID and other input parameters you have specified.

True

Comment Incident

Adds a comment to a specific incident on the Fortinet FortiSIEM server based on the incident ID you have specified.

True

Clear Incident With Reason

Clears an incident with the reason you have specified on the Fortinet FortiSIEM server based on the incident ID you have specified.

True

Get Events For Incident

Retrieves all associated events for a specified incident from the Fortinet FortiSIEM server, based on the incident ID and other input parameters you have specified.

True

Search Events

Searches for events in the Fortinet FortiSIEM server based on search attributes and other input parameters you have specified.

True

Get Event Details

Retrieves details of a specific event from the Fortinet FortiSIEM server based on the event ID you have specified and optionally the date range you have specified.

True

Get All Devices

Retrieves a short description for all devices that are configured on the Fortinet FortiSIEM server.

True

Get All Devices For Specified IP Address Range

Retrieves a short description for devices that are configured on the Fortinet FortiSIEM server, based on the IP address range that you have specified.

True

Get Device Information

Retrieves details of a specific device that is configured on the Fortinet FortiSIEM server, based on the Device IP that you have specified.

True

List Monitored Devices and Attributes

Retrieves a list and attributes of all monitored devices that are configured on the Fortinet FortiSIEM server.

True

List Monitored Organizations

Retrieves a list and details of all monitored organizations that are configured on the Fortinet FortiSIEM server.

True

Get Organization Details

Retrieves the details of a specific organization from the Fortinet FortiSIEM server based on the organization ID that you have specified.

True

Run Advanced Search Query

Runs an advanced search query on the Fortinet FortiSIEM server, based on the search conditions and other input parameters you have specified.

True

Get Event Attributes

Retrieves all event attributes from the Fortinet FortiSIEM server.

True

Get Events Data By Query ID

Retrieves data for events or incidents from the Fortinet FortiSIEM server based on the executed query ID you have specified.

True

Create Watch List

Creates a watch list in the FortiSIEM database. A watch list can contain one or more watch list entries.

True

Get Watch Lists

Retrieves details for all watch lists or for specific watch lists based on input parameters you have specified.

True

Get Watch List Entries Count

Returns the count of all watch list entries from all watch lists in Fortinet FortiSIEM.

True

Get Watch List Entry

Retrieves the specific watch list entry from Fortinet FortiSIEM based on the watch list entry ID you have specified.

True

Add Watch List Entries to Watch List

Adds watch list entries to one or more watch lists based on watch list ID and other input parameters you have specified.

True

Update Watch List Entry

Updates a watch list entry in the FortiSIEM database based on the watch list entry ID and other input parameters you have provided.

True

Delete Watch List Entry

Deletes watch list entries from the FortiSIEM database based on the ID of the watch list entries you have specified.

True

Delete Watch List

Deletes watch lists from the FortiSIEM database based on the ID of the watch lists you have specified.

True

Create Lookup Table

Creates the definition of a lookup table in the FortiSIEM server based on the name, column list, and other input parameters you have specified.

True

Get All Lookup Table

Retrieves the list of all lookupTable definitions from the FortiSIEM server based on the input parameters you have specified.

True

Delete Lookup Table

Deletes the lookupTable definition from the FortiSIEM server based on the lookup table ID you have specified.

True

Import Lookup Table Data

Imports the data of a specific CSV file in FortiSOAR to a specific lookup table in FortiSIEM based on the File/Attachment IRI, lookup table ID, and other input parameters you have specified.

True

Check Import Task Status

Checks the status of the import lookup table data task in FortiSIEM based on the lookup table ID and task ID you have specified.

True

Get Lookup Table Data

Retrieves items of the specified lookup table from FortiSIEM based on the lookup table ID and other input parameters you have specified.

True

Update Lookup Table Data

Updates items of a specified lookup table based on the lookup table ID, key, column data, and other input parameters you have specified.

True

Delete Lookup Table Data

Delete items of the specified lookup table in FortiSIEM based on the lookup table ID and primary keys you have specified.

True

Get IP Context

Retrieves the contextual data of the specified IP such as hostname, device type, location, device properties and known device information.

True

Get Host Context

Retrieves the contextual data of the specified hostname such as device type, and domain lookup information if an FQDN is supplied.

True

Get User Context

Retrieves the contextual data of the specified user such as known groups, location data, and top event types associated with this user account.

True

Pass
PlayBook Description Non Camel Case
PlayBooks NameDescriptionCamel Case

Run Advanced Search Query

Runs an advanced search query on the Fortinet FortiSIEM server, based on the search conditions and other input parameters you have specified.

True

Get Incident Details

Retrieves details of an incident from the Fortinet FortiSIEM server based on the incident IDs you have specified.

True

Get Watch List Entry

Retrieves the specific watch list entry from Fortinet FortiSIEM based on the watch list entry ID you have specified.

True

Delete Watch List Entry

Deletes watch list entries from the FortiSIEM database based on the ID of the watch list entries you have specified.

True

Get Watch List Entries Count

Returns the count of all watch list entries from all watch lists in Fortinet FortiSIEM.

True

Clear Incident With Reason

Clears an incident with the reason you have specified on the Fortinet FortiSIEM server based on the incident ID you have specified.

True

Delete Lookup Table

Deletes the lookupTable definition from the FortiSIEM server based on the lookup table ID you have specified.

True

Create Lookup Table

Creates the definition of a lookup table in the FortiSIEM server based on the name, column list, and other input parameters you have specified.

True

Get Host Context

Retrieves the contextual data of the specified hostname such as device type, and domain lookup information if an FQDN is supplied.

True

Get Organization Details

Retrieves the details of a specific organization from the Fortinet FortiSIEM server based on the organization ID that you have specified.

True

Search Events

Searches for events in the Fortinet FortiSIEM server based on search attributes and other input parameters you have specified.

True

Get User Context

Retrieves the contextual data of the specified user such as known groups, location data, and top event types associated with this user account.

True

List Monitored Devices and Attributes

Retrieves a list and attributes of all monitored devices that are configured on the Fortinet FortiSIEM server.

True

Get Event Details

Retrieves details of a specific event from the Fortinet FortiSIEM server based on the event ID you have specified and optionally the date range you have specified.

True

Get All Devices For Specified IP Address Range

Retrieves a short description for devices that are configured on the Fortinet FortiSIEM server, based on the IP address range that you have specified.

True

Delete Lookup Table Data

Delete items of the specified lookup table in FortiSIEM based on the lookup table ID and primary keys you have specified.

True

Get Watch Lists

Retrieves details for all watch lists or for specific watch lists based on input parameters you have specified.

True

> FortiSIEM > Fetch

This playbook fetch the open incidents.

True

FortiSIEM > Ingest

This playbook demonstrate the list incident operation.

True

Get Device Information

Retrieves details of a specific device that is configured on the Fortinet FortiSIEM server, based on the Device IP that you have specified.

True

Get All Devices

Retrieves a short description for all devices that are configured on the Fortinet FortiSIEM server.

True

List Monitored Organizations

Retrieves a list and details of all monitored organizations that are configured on the Fortinet FortiSIEM server.

True

Comment Incident

Adds a comment to a specific incident on the Fortinet FortiSIEM server based on the incident ID you have specified.

True

Update Lookup Table Data

Updates items of a specified lookup table based on the lookup table ID, key, column data, and other input parameters you have specified.

True

>> FortiSIEM > Fetch Associated events for Incident

Fetch Associated events for Incident.

True

Add Watch List Entries to Watch List

Adds watch list entries to one or more watch lists based on watch list ID and other input parameters you have specified.

True

Update Watch List Entry

Updates a watch list entry in the FortiSIEM database based on the watch list entry ID and other input parameters you have provided.

True

Get Lookup Table Data

Retrieves items of the specified lookup table from FortiSIEM based on thelookup table ID and other input parameters you have specified.

True

Update Incident

Updates the attributes of a specific incident on the Fortinet FortiSIEM server based on the incident ID and other input parameters you have specified.

True

Get Event Attributes

Retrieves all event attributes from the Fortinet FortiSIEM server.

True

Import Lookup Table Data

Imports the data of a specific CSV file in FortiSOAR to a specific lookup table in FortiSIEM based on the File/Attachment IRI,lookup table ID, and other input parameters you have specified.

True

Get Events Data By Query ID

Retrieves data for events or incidents from the Fortinet FortiSIEM server based on the executed query ID you have specified.

True

Delete Watch List

Deletes watch lists from the FortiSIEM database based on the ID of the watch lists you have specified.

True

Get Events For Incident

Retrieves all associated events for a specified incident from the Fortinet FortiSIEM server, based on the incident ID and other input parameters you have specified.

True

Create Watch List

Creates a watch list in the FortiSIEM database. A watch list can contain one or more watch list entries.

True

List Incidents

Retrieves a list and details of incidents from the Fortinet FortiSIEM server based on the time range, and other filter criteria you have specified. NOTE:The FortiSIEM API does not support filtering incidents in the "List Incident" action based on sub-categories.

True

Get IP Context

Retrieves the contextual data of the specified IP such as hostname, device type, location, device properties and known device information.

True

Check Import Task Status

Checks the status of the import lookup table data task in FortiSIEM based on thelookup table ID and task ID you have specified.

True

Get All Lookup Table

Retrieves the list of all lookupTable definitions from the FortiSIEM server based on the input parameters you have specified.

True

Pass
PlayBook Collection Description Non Camel Case
PlayBooks Collection DescriptionNon Camel Case

Sample playbooks for "Fortinet FortiSIEM" connector. If you are planning to use any of the sample playbooks in your environment, ensure that you clone those playbooks and move them to a different collection, since the sample playbook collection gets deleted during connector upgrade and delete.

True

Pass
Action Name is in Camel Case
Action NameCamel Case

List Incidents

True

Get Incident Details

True

Update Incident

True

Comment Incident

True

Clear Incident With Reason

True

Get Events For Incident

True

Search Events

True

Get Event Details

True

Get All Devices

True

Get All Devices For Specified IP Address Range

True

Get Device Information

True

List Monitored Devices and Attributes

True

List Monitored Organizations

True

Get Organization Details

True

Run Advanced Search Query

True

Get Event Attributes

True

Get Events Data By Query ID

True

Create Watch List

True

Get Watch Lists

True

Get Watch List Entries Count

True

Get Watch List Entry

True

Add Watch List Entries to Watch List

False

Update Watch List Entry

True

Delete Watch List Entry

True

Delete Watch List

True

Create Lookup Table

True

Get All Lookup Table

True

Delete Lookup Table

True

Import Lookup Table Data

True

Check Import Task Status

True

Get Lookup Table Data

True

Update Lookup Table Data

True

Delete Lookup Table Data

True

Get IP Context

True

Get Host Context

True

Get User Context

True

Fail

Playbooks are Inactive
PlayBooks NameInActive

Run Advanced Search Query

True

Get Incident Details

True

Get Watch List Entry

True

Delete Watch List Entry

True

Get Watch List Entries Count

True

Clear Incident With Reason

True

Delete Lookup Table

True

Create Lookup Table

True

Get Host Context

True

Get Organization Details

True

Search Events

True

Get User Context

True

List Monitored Devices and Attributes

True

Get Event Details

True

Get All Devices For Specified IP Address Range

True

Delete Lookup Table Data

True

Get Watch Lists

True

> FortiSIEM > Fetch

True

FortiSIEM > Ingest

True

Get Device Information

True

Get All Devices

True

List Monitored Organizations

True

Comment Incident

True

Update Lookup Table Data

True

>> FortiSIEM > Fetch Associated events for Incident

True

Add Watch List Entries to Watch List

True

Update Watch List Entry

True

Get Lookup Table Data

True

Update Incident

True

Get Event Attributes

True

Import Lookup Table Data

True

Get Events Data By Query ID

True

Delete Watch List

True

Get Events For Incident

True

Create Watch List

True

List Incidents

True

Get IP Context

True

Check Import Task Status

True

Get All Lookup Table

True

Pass
Playbook Names in Camel Case
PlayBooks NameCamel Case

Run Advanced Search Query

True

Get Incident Details

True

Get Watch List Entry

True

Delete Watch List Entry

True

Get Watch List Entries Count

True

Clear Incident With Reason

True

Delete Lookup Table

True

Create Lookup Table

True

Get Host Context

True

Get Organization Details

True

Search Events

True

Get User Context

True

List Monitored Devices and Attributes

True

Get Event Details

True

Get All Devices For Specified IP Address Range

True

Delete Lookup Table Data

True

Get Watch Lists

True

> FortiSIEM > Fetch

True

FortiSIEM > Ingest

True

Get Device Information

True

Get All Devices

True

List Monitored Organizations

True

Comment Incident

True

Update Lookup Table Data

True

>> FortiSIEM > Fetch Associated events for Incident

False

Add Watch List Entries to Watch List

False

Update Watch List Entry

True

Get Lookup Table Data

True

Update Incident

True

Get Event Attributes

True

Import Lookup Table Data

True

Get Events Data By Query ID

True

Delete Watch List

True

Get Events For Incident

True

Create Watch List

True

List Incidents

True

Get IP Context

True

Check Import Task Status

True

Get All Lookup Table

True

Fail

Playbook Collection Name in Camel Case
PlayBook Collection NameCamel Case

Sample - Fortinet FortiSIEM - 5.2.1

True

Pass
Check Image Sizes
imageCorrect size
fortisiem_small.pngTrue
fortisiem_large.pngTrue
Pass
Check Online Help Doc Present
Help Doc LinkDoc Link Present

https://docs.fortinet.com/document/fortisoar/5.2.1/fortinet-fortisiem/847/fortinet-fortisiem-v5-2-1

True

Pass
PlayBook Tag
PlayBooks NameTag Present

Run Advanced Search Query

True

Get Incident Details

True

Get Watch List Entry

True

Delete Watch List Entry

True

Get Watch List Entries Count

True

Clear Incident With Reason

True

Delete Lookup Table

True

Create Lookup Table

True

Get Host Context

True

Get Organization Details

True

Search Events

True

Get User Context

True

List Monitored Devices and Attributes

True

Get Event Details

True

Get All Devices For Specified IP Address Range

True

Delete Lookup Table Data

True

Get Watch Lists

True

> FortiSIEM > Fetch

True

FortiSIEM > Ingest

True

Get Device Information

True

Get All Devices

True

List Monitored Organizations

True

Comment Incident

True

Update Lookup Table Data

True

>> FortiSIEM > Fetch Associated events for Incident

True

Add Watch List Entries to Watch List

True

Update Watch List Entry

True

Get Lookup Table Data

True

Update Incident

True

Get Event Attributes

True

Import Lookup Table Data

True

Get Events Data By Query ID

True

Delete Watch List

True

Get Events For Incident

True

Create Watch List

True

List Incidents

True

Get IP Context

True

Check Import Task Status

True

Get All Lookup Table

True

Pass
PlayBook Debug Mode
PlayBooks NameDebug Off

Run Advanced Search Query

True

Get Incident Details

True

Get Watch List Entry

True

Delete Watch List Entry

True

Get Watch List Entries Count

True

Clear Incident With Reason

True

Delete Lookup Table

True

Create Lookup Table

True

Get Host Context

True

Get Organization Details

True

Search Events

True

Get User Context

True

List Monitored Devices and Attributes

True

Get Event Details

True

Get All Devices For Specified IP Address Range

True

Delete Lookup Table Data

True

Get Watch Lists

True

> FortiSIEM > Fetch

True

FortiSIEM > Ingest

True

Get Device Information

True

Get All Devices

True

List Monitored Organizations

True

Comment Incident

True

Update Lookup Table Data

True

>> FortiSIEM > Fetch Associated events for Incident

True

Add Watch List Entries to Watch List

True

Update Watch List Entry

True

Get Lookup Table Data

True

Update Incident

True

Get Event Attributes

True

Import Lookup Table Data

True

Get Events Data By Query ID

True

Delete Watch List

True

Get Events For Incident

True

Create Watch List

True

List Incidents

True

Get IP Context

True

Check Import Task Status

True

Get All Lookup Table

True

Pass
Connector Publisher and CS Approved
Is CS ApprovedPublisher
TrueFortinet
Pass
Atleast One Action Present
One Action PresentAction Available

List Incidents

True

Pass
Check Requirements File
Requirement Txt PackageVersion Available

xmltodict

False

Pass