|
Elastic/Kibana integration with TheHive
|
|
0
|
793
|
August 19, 2022
|
|
Detecting inactive users in Active Directory
|
|
5
|
1820
|
January 25, 2023
|
|
Endpoint 7.12.x migration to 7.13 Lesson learned with Fleet "On-Prim"
|
|
7
|
851
|
June 11, 2021
|
|
Remove or Hide Kibana and Signal fields in Elastic Security
|
|
8
|
1399
|
January 26, 2022
|
|
Active Directory logs and mapping to ECS (I am stumped)
|
|
6
|
8752
|
October 14, 2019
|
|
Osquery Manager Feedback - Linux AARCH64 - Raspberry Pi
|
|
1
|
906
|
May 26, 2021
|
|
Log4j Critical Vulnerability
|
|
1
|
2800
|
December 10, 2021
|
|
Elastic SIEM Rules/Exceptions/Lists in Terraform
|
|
0
|
681
|
April 18, 2022
|
|
Use of Indicator Match Rules using Cross Cluster Search
|
|
7
|
1290
|
February 7, 2023
|
|
Anyone have success using Machine Learning to detect Fast or Impossible Travel?
|
|
6
|
2402
|
November 16, 2021
|
|
Error when installing fleet server
|
|
8
|
6635
|
June 10, 2021
|
|
Threshold Rule for Detecting Brute force Attacks
|
|
6
|
3741
|
October 7, 2020
|
|
Installing ElasticAgent with GPO
|
|
5
|
3986
|
May 11, 2022
|
|
Creating a case for an alert automatically
|
|
2
|
1693
|
January 27, 2022
|
|
Elastic-Agent installed, but not viewable in Security Hosts tab or logs in Kibana
|
|
8
|
2966
|
March 7, 2022
|
|
Limit CPU/Memory usage in Auditbeat & Filebeats , version 7.9.0
|
|
7
|
5445
|
September 17, 2020
|
|
How to stop Elastic Endpoint
|
|
5
|
6170
|
March 15, 2021
|
|
Multiple Different Clients
|
|
4
|
2057
|
January 4, 2021
|
|
Event Correlation on ELK
|
|
2
|
7987
|
August 26, 2019
|
|
Plans to Support System Firewall Management?
|
|
0
|
437
|
June 28, 2022
|
|
Fleet Server won't start - certificate error
|
|
2
|
7333
|
June 3, 2021
|
|
Error with Security Rules
|
|
8
|
2372
|
May 23, 2022
|
|
Can I still use Threat Intelligence?
|
|
6
|
823
|
November 29, 2022
|
|
Endpoint Security Intergration vs. Windows and System Intergrations
|
|
2
|
1247
|
February 9, 2022
|
|
Curl: (77) Problem with the SSL CA cert (path? access rights?)
|
|
4
|
5324
|
August 10, 2023
|
|
Create a rule that alerts on out of hours
|
|
3
|
1760
|
February 24, 2023
|
|
Feature Request for more robust vector graphics (Vega not enough) so I can generate good looking network maps (non-geographic)
|
|
2
|
625
|
March 23, 2023
|
|
Import rules from public detection rules repo
|
|
2
|
1959
|
August 18, 2020
|
|
End point security fails for Elastic Agent with error "Missed two check-ins"
|
|
5
|
4312
|
February 18, 2022
|
|
Elastic Agent (Fleet Deployment) behind a proxy
|
|
6
|
2225
|
November 4, 2020
|
|
EQL detection rule run on indices created by Transforms
|
|
2
|
1045
|
March 24, 2021
|
|
Hosts table : host.name (alias of beat.name) used instead of agent.hostname
|
|
1
|
3968
|
February 17, 2020
|
|
Updating the alerting for all rules with the API
|
|
0
|
313
|
April 22, 2022
|
|
Timeline Template see fields other then the fields in the alert
|
|
4
|
435
|
February 8, 2024
|
|
Seperate email alerts per detection?
|
|
2
|
560
|
May 17, 2022
|
|
Complete DNS activity coverage in endpoint
|
|
1
|
684
|
November 23, 2021
|
|
Fleet Server - Error - x509: certificate is valid for 127.0.0.1, not x.x.x.x
|
|
2
|
5555
|
May 30, 2022
|
|
Elastic agent unhealthy because of elastic defend integration
|
|
5
|
3858
|
August 26, 2023
|
|
Fleet server agent unable to start- Connection refused
|
|
3
|
4693
|
October 7, 2021
|
|
Rules not triggering alerts
|
|
5
|
3830
|
September 21, 2021
|
|
"Machine learning permission error" for demo user
|
|
1
|
1158
|
June 25, 2020
|
|
Filebeat for Sophos XG Firewall
|
|
8
|
3043
|
August 7, 2019
|
|
Error: Get "http://unix/": dial unix /opt/Elastic/Agent/data/tmp/default/endpoint-security/endpoint-security.sock: connect: no such file or directory
|
|
4
|
4066
|
May 2, 2022
|
|
Elastic agent and SvcHost DnsCache very high CPU usage
|
|
8
|
1693
|
May 31, 2022
|
|
Hosts duplicated with and without fqdn
|
|
6
|
1918
|
June 30, 2020
|
|
Detection Rules Fail Index issues
|
|
8
|
2999
|
January 29, 2021
|
|
SIEM ECS descriptions taking huge amount of unneccesary space in SIEM
|
|
1
|
624
|
September 27, 2019
|
|
Elastic agent shows healthy (Also no error messages in Logs) in Kibana but fails to send data to elastic search
|
|
5
|
3583
|
May 5, 2022
|
|
Unable to change the elastic-agent grpc.port during fleet server setup
|
|
2
|
4885
|
October 11, 2021
|
|
Detections coverage of ATT&CK documentation
|
|
3
|
745
|
April 15, 2021
|