Purpose
This SOP outlines the steps required to
whitelist an IP address in FortiSIEM by editing an existing rule and adding an
exception based on source or destination IP.
Prerequisites
- Access to FortiSIEM Supervisor with admin
super account credentials.
- Knowledge of the rule for which the IP needs to be whitelisted.
Procedure
1.
Login to FortiSIEM Supervisor
using your admin super account.
2.
Navigate to the 'Resources'
section.
3.
Go to the 'Rules' tab.
4.
Search for the rule you want to
modify to whitelist the IP address.
5.
Select the rule and click
'Edit'.
6.
Navigate to the 'Define Action'
section.
7.
Go to the 'Exception' tab.
8.
Define the exception by
specifying the Source IP or Destination IP to be whitelisted.
9.
Click 'Save' to apply the
changes.
Notes
- Ensure that the IP address being
whitelisted is verified and approved.
- Changes to rules may impact event handling and alerting; review thoroughly
before saving.
No comments:
Post a Comment