Join the Community
Hi Bruno,You say some properties are not being extracted but your screenshot actually indicates that a particular QID is no longer showing up. This is a different kind of problem as the QID is not extracted from the raw event, rather it is looked up based on the Event ID and Event Category determined by the DSM as part of its processing logic. It could be that there was a change where the Event ID or Event Category are now being set differently, or they may now map to a different QID record. Neither should happen unless absolutely necessary, and even then we would usually have a migration option of some kind, so I think something did go wrong here, I will raise it with the team.Are there other QIDs you've noticed are no longer appearing, or are there any other properties that are not being populated as they were before?
Can you provide a sample event payload for one of the events returned by the search in your screenshot? If so, please replace any usernames/IPs/hostnames/etc with placeholders values to protect your organization's privacy.CheersColin
Bruno,In the last Fortigate DSM update some QIDs/Event Mappings changed.
We had the same problem, so maybe you can find the new event searching by event name.