# Elastic - MISP Integration shows total Indicators ( fortigate logs)

**URL:** <https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132>\
**Category:** SIEM\
**Tags:** painless\
**Created:** [February 20, 2026, 6:42am UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132 "2026-02-20T06:42:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![4l13v](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/4l13v/32/146872_2.png) [@4l13v](https://discuss.elastic.co/u/4l13v)\
**Post date:** [February 20, 2026, 6:42am UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132/1 "2026-02-20T06:42:01Z")

</div>

Hello community. I am having big issue right now.  
I have Integrated Fortigate and Elastic. Then attempted to integrate MISP to Elastic. Integration was well till [Logs MISP] Dashboard was thinking Total Indicators count is actually fortigate logs.( screenshot 1)

When I click to “explore in discover”, it redirected me to Fortigate logs (screenshot 2)

My main mission is match the fortigate destination Ips with MISP’s feed database.

 ![Screenshot_4](https://us1.discourse-cdn.com/elastic/original/3X/3/1/313e186a0cf5e6f4c59f99d84d478b19f7e055f1.png)

---

<div class="post-metadata">

**Author:** ![4l13v](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/4l13v/32/146872_2.png) [@4l13v](https://discuss.elastic.co/u/4l13v)\
**Post date:** [February 20, 2026, 6:42am UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132/2 "2026-02-20T06:42:43Z")

</div>

screenshot 2 ( Total Indicators view in discover session)

 ![Screenshot_1](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9e150ec9265970d34d41cb960a1c0feb59569415.png)

---

<div class="post-metadata">

**Author:** ![sdesalas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sdesalas/32/146614_2.png) [@sdesalas](https://discuss.elastic.co/u/sdesalas)\
**Post date:** [February 23, 2026, 1:23pm UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132/3 "2026-02-23T13:23:50Z")

</div>

Hi 👋 **4l13v**

I think what you’re seeing is probably caused by the **MISP dashboard querying the wrong data view** , not because FortiGate logs are actually becoming MISP indicators.

### **What I think is happening**

- The **[Logs MISP] dashboard** is built to work only with **MISP indicator documents**.

- In your case, the dashboard’s **data view/index pattern probably includes FortiGate indices** (for example something like **`logs-*`** ).

- Because of that:

So I don’t really think that the dashboard is broken — it’s probably just **not filtered to MISP data only**.

### **What to check first**

1. **Data View used by the MISP dashboard**

2. **Event filtering**

### **About matching FortiGate IPs with MISP indicators**

Elastic does **not automatically match** FortiGate destination IPs with MISP feeds just by ingesting both.

To achieve that, you need one of the following:

- **Indicator Match detection rule**  
(Security → Rules → Indicator Match)

**or**

- **Threat Intel enrichment / enrich policy**

Until one of these is configured, FortiGate logs and MISP indicators will remain **separate datasets**.

### **Summary**

- The MISP dashboard is likely counting FortiGate logs because of a **shared data view**

- Its possible to fix the **index pattern / filters** so it only targets MISP data

- Use **Indicator Match rules or enrichment** to correlate FortiGate IPs with MISP

Hope this helps!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 23, 2026, 6:03pm UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132/4 "2026-02-23T18:03:24Z")

</div>

> [@sdesalas](#):
>
> So I don’t really think that the dashboard is broken — it’s probably just **not filtered to MISP data only**.

The dashboard is a Managed Dashboard, it is built by Elastic and it is part of the MISP integration, the user has no control over it and cannot edit the visualizations.

I have the same issue:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/0/3029df684c93fc8209cf2706e8d96398584822e9.png)

The visualization configuration is pointing to `logs-*` without filtering with `event.module: ti_misp`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d81c6d00720073f47f472afc491b1e041f20628f.png)

So, if a visualization on the MISP dashboard may not show MISP events because it is missing a filter, than I think that the dashboard is broken, it needs to be fixed by Elastic as it is part of an integration.

If you want I can open a Github Issue.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 23, 2026, 6:16pm UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132/5 "2026-02-23T18:16:32Z")

</div>

Just opened an issue: [[TI\_MISP] Dashboard visualization showing data from other datasets and not showing MISP data · Issue #17524 · elastic/integrations · GitHub](https://github.com/elastic/integrations/issues/17524)

---

<div class="post-metadata">

**Author:** ![sdesalas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sdesalas/32/146614_2.png) [@sdesalas](https://discuss.elastic.co/u/sdesalas)\
**Post date:** [February 24, 2026, 11:07am UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132/6 "2026-02-24T11:07:56Z")

</div>

Hi Leandro. You’re right, I didnt realize this was a dashboard for a managed integration.

Thanks for creating bug ticket 🙏 . I can see this has been assigned to the Security Integrations teams which would be the team responsible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2026, 11:08am UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132/7 "2026-03-24T11:08:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
