Integrate FortiSIEM

FortiSIEM is an advanced Security Information and Event Management (SIEM) solution that combines advanced log and traffic analysis with performance/availability monitoring, change analysis, and accurate knowledge of the infrastructure to provide accurate threat detection, remediation, incident response, and compliance reporting. See https://www.fortinet.com/products/siem. You can protect access to FortiSIEM by integrating FortiSIEM with Identity as a Service. Once integrated, users can use single sign-on to log in to their FortiSIEM account through Identity as a Service.

Note: This integration was tested using Identity as a Service version 5.32 and FortiSIEM version VA 7.0.2.0043. Other versions of FortiSIEM may require integration and configuration steps that differ from those documented in this procedure. For other versions of FortiSIEM, this integration guide may be used as an initial approach for integrating FortiSIEM. In the event of other issues, contact support@entrust.com for assistance.

To integrate FortiSIEM with Identity as a Service, you must do the following:

Step 1: Copy the SAML Configuration from Identity as a Service

Step 2: Copy the signing certificate from Identity as a Service

Step 3: Configure FortiSIEM for Identity as a Service authentication

Step 4: Add FortiSIEM to Identity as a Service

Step 5: Create a resource rule to protect access to FortiSIEM

Step 6: Test the integration