Skip to main content
Visitor III
May 5, 2026
Question

How should a Daily Global Report be configured? And is AI Integration in FortiSIEM Possible?

  • May 5, 2026
  • 5 replies
  • 97 views

Hi everyone,!

I'm working on optimising my FortiSIEM reporting, and I have two specific questions for the community:

1. Daily Global Report Configuration
I want to generate a "Daily Global Report" that covers everything (incidents, config changes, and system health, etc) for the last 24 hours.

  • What is the best way to group this into a single automated task?

2. AI Integration (Inside or Outside FortiSIEM)
I'm interested in using AI to analyze or summarize these reports.

  • If you use an external AI, how do you securely connect it to FortiSIEM to pull data automatically?

Thanks in advance for your insights!

5 replies

Secusaurus
Contributor III
May 5, 2026

Hi ​@ghr,

 

Regarding the first question, have a look at report bundles: 

 

For your second question: What kind of data would you like to pull?

Best,

Christian

NSE8 | Fortinet Advanced MSSP Partner
ghrAuthor
Visitor III
May 5, 2026

Hi ​@Secusaurus ,

Thank you so much for your help! Following your advice, I managed to successfully create and schedule my general activity report. It’s working perfectly now.

I’m now looking to take it to the next level using AI to make the report insights more relevant (better anomaly detection or summarization). Do you have any experience or ideas on:

  1. External Processing: Sending report data to an external application to be analyzed by an AI/ML?
  2. Internal Integration: Is there a way to leverage FortiSIEM’s built-in UEBA or ML features to enhance the report details directly inside the platform?

Thanks again for your valuable time!

Best regards,
Ghada

Secusaurus
Contributor III
May 6, 2026

Hi Ghada,

 

concerning AI processing: I think, most of the LLMs (local ones or cloud-based commercial ones) will work very good with a simple pre-prompt and getting the report. We do some kind of this the other way round: Scraping the internet for CVE and press information and piping this into an LLM by an open source automation tool regularly. That works quite well.

 

The UEBA and ML features of FortiSIEM are targeting the generation of Incidents. You can leverage them to get meaningful Incidents, but you will still end up with the report tables.

In 7.5.x, there are a lot of “FortiAI”-features that help to get more and “meaningful” (whatever that means using a hallucinating LLM...) insights into Events, Incidents and Cases, but these are currently only meant to work on the FSM GUI itself, not for reports.

 

Best,

Christian

NSE8 | Fortinet Advanced MSSP Partner
ghrAuthor
Visitor III
May 6, 2026

Hi Christian,

Thank you for these valuable insights! It’s great to hear that you’ve had success using LLMs with external automation tools—it confirms that my plan to use an external application for advanced reporting is the right direction.

You mentioned using "open source automation tools" to pipe data into LLMs. Could you please share which specific tools you recommend or have had success with? 
 

Thanks again for the update on the new release!

 

Best regards,

Ghada

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.