SIEM exported logs do not have the medium or high incidents shown in the Detect incident section under event logs.
Component: Investigate
Detect Incidents currently can only be exported from the Detect module.
To export these incidents, go to Detect, then Incidents, and then click the Export Incidents option.
Because the Detect admin can adjust the Severity Thresholds, the resulting severity level might change. The admin can also use ThreatScore as a reference.