Skip to content
Playbook All on Content Hub

Data ingestion template

Fetch / Create / Ingest skeleton for building a connector-based alert ingestion.

@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Sep 20, 2026
Download JSON · 24 KB

data-ingestion-template.json

sha256:8d648dda2d82114b6992be8ef9e0d07c6647358f292d33bead881ea424acf3d8

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

The three-playbook layout the Data Ingestion Wizard expects: Fetch pulls raw records, Create maps one record to an alert, Ingest orchestrates the two.

Replace the placeholder steps (they raise an exception on purpose) with your connector's fetch operation and field mapping.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000