FortiSIEM Data Ingest Issue
Hello Guys,
I’m encountering two issues while trying to retrieve incidents from FortiSIEM. I’d appreciate your assistance with these matters.
1. When ingesting data, even though I specify a count for “pull request” and “per page,” when I click “trigger,” it tries to retrieve all incidents, and the count in the alert suddenly spikes. How can we resolve this?
2. We wanted to retrieve specific incidents from FortiSIEM using the Incident ID, but we observed that the content does not include the entire raw log from FortiSIEM—only the incident details. For example, we cannot see fields such as “source” and “dest IP” from the raw log in SOAR, so we are unable to create a map even if we wanted to. Can we expand the content of the raw log sent to SOAR?
Thanks in advance
