Skip to main content
khilfi
New Member
May 29, 2025
Question

Make Alert Source Data Appears on Alert Table List

  • May 29, 2025
  • 2 replies
  • 599 views

Hi all,

 

I am fairly new with FortiSOAR and trying to get my head around on how to use it. I already managed to ingest data from the SIEM into the alert module and by default, the columns displayed and can be filtered are such as severity and ID. Now, I am trying to fill up this alert table with some data/fields of the ingested data from the SIEM into the alert table. I can see the data is in the source data tab inside the alert. Need some help to point me on how to make it happen. Pointing me to the correct documentation will also be very helpfull

2 replies

jankit6
Staff
Staff
May 29, 2025

Hello @khilfi 

Kindly refer to the section "Data Ingestion Support" in the document below:

https://docs.fortinet.com/document/fortisoar/5.4.1/fortinet-fortisiem/1059/fortinet-fortisiem-v5-4-1#dataIngestion

You can map the fields extracted from the source either from the data ingestion wizard or the create records step in the ingestion playbook.

 

Thanks

 

khilfi
khilfiAuthor
New Member
June 3, 2025

This seems to be the solution that I need, I'll look into it more.

 

Thanks for the help

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!