Skip to main content
adem_netsys
Explorer III
July 10, 2026
Question

FortiSIEM Data Ingest Issue

  • July 10, 2026
  • 0 replies
  • 18 views

Hello Guys,

I’m encountering two issues while trying to retrieve incidents from FortiSIEM. I’d appreciate your assistance with these matters.

1. When ingesting data, even though I specify a count for “pull request” and “per page,” when I click “trigger,” it tries to retrieve all incidents, and the count in the alert suddenly spikes. How can we resolve this?

 

2. We wanted to retrieve specific incidents from FortiSIEM using the Incident ID, but we observed that the content does not include the entire raw log from FortiSIEM—only the incident details. For example, we cannot see fields such as “source” and “dest IP” from the raw log in SOAR, so we are unable to create a map even if we wanted to. Can we expand the content of the raw log sent to SOAR?

 

Thanks in advance

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!