# Integration FortiDLP to Elastic SIEM

**URL:** <https://discuss.elastic.co/t/integration-fortidlp-to-elastic-siem/378724>\
**Category:** Elastic Security\
**Created:** [May 30, 2025, 8:28am UTC](https://discuss.elastic.co/t/integration-fortidlp-to-elastic-siem/378724 "2025-05-30T08:28:01Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [May 30, 2025, 8:28am UTC](https://discuss.elastic.co/t/integration-fortidlp-to-elastic-siem/378724/1 "2025-05-30T08:28:01Z")

</div>

Hello,

Just wanted to ask if its possible to intergrate FortiDLP with Elastic...if so based on the methode or mode below can we use :

### **Event ingestion modes**

The Event Streaming Service supports two modes of event ingestion:

- Websocket mode: A mode in which the SIEM tool connects to the API via a websocket connection. In this mode, the websocket connection maintains a persistent connection to the event stream, meaning events are continuously streamed to the SIEM tool.
- Long polling mode: A mode in which the SIEM tool requests a batch of events from the API via HTTP. In this mode, the batch of events received includes those already queued in the stream and/or those queued within 30 seconds from the time of the request.

Your assistance will be appreciated

Thanks
