Skip to main content
nsoni
Staff
Staff
February 11, 2026

Technical Tip: 'Rule Name' attribute is blank when added as display field in 'All Incidents' system report

  • February 11, 2026
  • 0 replies
  • 77 views
Description This article provides steps to add rule names for respective incidents in the 'All Incidents' report.
Scope FortiSIEM v7.x and above.
Solution

Note that the 'Rule Name' attribute does not exist for internal incident events returned by analytics query 'System Event Category = 1'.

 

Follow these steps to see rule names in the 'All Incidents' report:

  1. Navigate to Resources -> Reports and run the report 'All Incidents'.
  2. In analytics, add 'Event Type' attribute to 'Group By and Display Fields' and select 'Apply & Run'.
  3. Rule names for the respective incident would be listed in the 'Event Name' column.
  4. Select the 'Actions' drop-down, followed by 'Save as Report' to create a custom report.

 

all_incidents_KB.png