I have not deployed this particular connector. There are two options, both used Syslog (CEF) forwarding for data collection. The solutions include logic apps and one function app. Both include or can easily be expanded to use secure API key storage like a Key Vault. I assume there are also ways to limit the key permissions. They appear to be supplemental automation. I recommend deploying the solutions so you can take a closer look followed by a pilot of the agent-base data connector. It is also likely that the solutions were provided by Fortinet rather than Microsoft. Any person or vendor can submit solutions through GitHub for publishing to the solution marketplace after review.
Why use Fortinet Connector instead of a Function App for registering an action group in the Fortinet-FortiGate playbook?
mara7
166
Reputation points
Hello,
I am setting up the Fortinet-FortiGate playbook and noticed that for registering an action group in FortiGate, the playbook uses the Fortinet Connector instead of a Function App.
Why was the Fortinet Connector chosen for this action instead of a Function App? Wouldn’t using the Fortinet Connector pose a security risk due to potential API key exposure?
Thank you!
Microsoft Security Microsoft Sentinel
1,299 questions
1 answer
Sort by: Most helpful
-
Andrew Blumhardt 10,051 Reputation points Microsoft Employee
2025-02-12T12:53:32.88+00:00