Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | FortinetFortiNdrCloudDataConnector |
| Publisher | Fortinet |
| Used in Solutions | Fortinet FortiNDR Cloud |
| Collection Method | Azure Function |
| Connector Definition Files | FortinetFortiNdrCloud_API_AzureFunctionApp.json |
| Ingestion API | Log Ingestion API — Sibling ARM template declares DCR / Log Ingestion API resources |
| Microsoft Learn | View on Learn |
The Fortinet FortiNDR Cloud data connector provides the capability to ingest Fortinet FortiNDR Cloud data into Microsoft Sentinel using the FortiNDR Cloud API
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
FortinetFortiNdrCloudRaw_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
NOTE: This connector uses an enterprise application integration model via Azure Functions to securely pull logs from the FortiNDR Cloud API into Microsoft Sentinel. This deployment may incur data ingestion and compute costs. Check the Azure Functions pricing page for details.
(Optional Step) Securely store API authorization key(s) or token(s) in Azure Key Vault. Azure Key Vault provides a secure mechanism to store and retrieve key values. Follow these instructions to use Azure Key Vault with an Azure Function App.
NOTE: This connector uses a parser based on a Kusto Function to normalize fields. Follow these steps to create the Kusto function alias Fortinet_FortiNDR_Cloud.
STEP 1 - Deploy the connector and the associated Azure Function
IMPORTANT: Before deploying the Fortinet FortiNDR Cloud connector, have the value below, readily available.
WorkspaceIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
STEP 2 - Azure Resource Manager (ARM) Template
Use this method for automated deployment of the Fortinet FortiNDR Cloud connector.
Click the Deploy to Azure button below.
Select the preferred Subscription, Resource Group and Location.
Click Create to deploy.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊