I am working to integrate Fortigate logs. And like you most data is in Extraneous field. Plus for some reason the logs does not bring across the Web traffic URL (although we can see it in the Fortigate device log).
If anyone gets the figured out I would like to know what they did. We are adding some fortinet devices that I would love to monitor through LEM, but the data is not coming out nicely or usable at all.