FortiEDR

FortiEDR

This guide explains how to integrate Fortinet FortiEDR with RedCarbon.

Overview

The FortiEDR integration allows RedCarbon to ingest security events and alerts from the FortiEDR management console.

Configuration

To configure the integration, you need to create a dedicated API User in the FortiEDR management console.

Step 1: Create an API User

  1. Log in to the FortiEDR Management Console.
  2. Navigate to Administration > Users.
  3. Click Add User.

Add User

Step 2: Configure Settings

  1. Enter the User Name (e.g., RedCarbonAPI).
  2. Check the Rest API option to enable API access.
  3. Assign the appropriate Role (e.g., Admin or a custom role with Read permissions).
  4. Click Save.

Enable REST API

Step 3: Configure RedCarbon

  1. Log in to the RedCarbon Dashboard.
  2. Navigate to the customer's Integrations page.
  3. Select FortiEDR.
  4. Enter the FortiEDR URL, Username, and Password.
  5. Click Save and then Test.

Configure RedCarbon

Severity Mapping

Original SeverityRedCarbon Score
Low10
Medium40
High70
Critical90