Whathappens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
FortiAnalyzer flags the associated host for further analysis.
A new infected entry is added for the corresponding endpoint under Compromised Hosts.
The detection engine classifies those logs as Suspicious.
The endpoint is marked as Compromised and, optionally, can be put in quarantine.
Submit