FortiSOAR Discussions
khilfi
New Contributor

Make Alert Source Data Appears on Alert Table List

Hi all,

 

I am fairly new with FortiSOAR and trying to get my head around on how to use it. I already managed to ingest data from the SIEM into the alert module and by default, the columns displayed and can be filtered are such as severity and ID. Now, I am trying to fill up this alert table with some data/fields of the ingested data from the SIEM into the alert table. I can see the data is in the source data tab inside the alert. Need some help to point me on how to make it happen. Pointing me to the correct documentation will also be very helpfull

2 REPLIES 2
jankit6
Staff
Staff

Hello @khilfi 

Kindly refer to the section "Data Ingestion Support" in the document below:

https://docs.fortinet.com/document/fortisoar/5.4.1/fortinet-fortisiem/1059/fortinet-fortisiem-v5-4-1...

You can map the fields extracted from the source either from the data ingestion wizard or the create records step in the ingestion playbook.

 

Thanks

 

khilfi
New Contributor

This seems to be the solution that I need, I'll look into it more.

 

Thanks for the help