You need a filed to uniquely identify the exported CloudSOC Detect logs. You notice in the Detect management API export, there is the _id filed
{
"_id": XXXXXXXXXX_######",
"from_detect": 1,
..
}
but the same field cannot be found in the SIEM agent log export.
The CloudSOC engineering team is planning to include the _id filed in the SIEM agent log export in 3.184.