# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the SIEM category](https://discuss.elastic.co/t/about-the-siem-category/181817)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0

</div>

Security analytics at the speed of Elasticsearch Everything you love about the free and open Elastic Stack — geared toward security information and event management (SIEM). Leverage the speed, scale, and relevance of Ela…

---

## [Forwarding detection alert status changes (acknowledged / closed) to an external system](https://discuss.elastic.co/t/forwarding-detection-alert-status-changes-acknowledged-closed-to-an-external-system/390784)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [September 30, 2026, 6:17pm UTC](https://discuss.elastic.co/t/forwarding-detection-alert-status-changes-acknowledged-closed-to-an-external-system/390784 "2026-09-30T18:17:33Z")

</div>

Hello, We forward Elastic Security detection alerts to an external system through a Webhook connector configured as a rule action. That works well for new alerts. However, the receiving side also requires every subseque…

---

## [Sharing my rule update experience on Elastic Security Serverless](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 13\
**Last updated:** [September 25, 2026, 12:27pm UTC](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853 "2026-09-25T12:27:47Z")

</div>

Hello, Just sharing my experience updating Elastic prebuilt Security rules after being away for about 1.5 months. When I logged back in, I had roughly 1,200 rule updates waiting. That is fine in itself - I clicked Upda…

---

## [Auditd Logs 3.24.1 - "Use auditd parser" fails on Elastic 9.3.3 with Missing helper: semverSatisfies](https://discuss.elastic.co/t/auditd-logs-3-24-1-use-auditd-parser-fails-on-elastic-9-3-3-with-missing-helper-semversatisfies/389780)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [August 19, 2026, 2:20pm UTC](https://discuss.elastic.co/t/auditd-logs-3-24-1-use-auditd-parser-fails-on-elastic-9-3-3-with-missing-helper-semversatisfies/389780 "2026-08-19T14:20:03Z")

</div>

Hi all, We are testing the latest Auditd Logs integration, version 3.24.1, on an Elastic Stack running 9.3.3. The integration now has the experimental option: Use auditd parser (experimental) The description sounds…

---

## [Multiple Machine Learning Alerts by Influencer Field failing Unknown column \[job\_id\]](https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [August 18, 2026, 7:29am UTC](https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743 "2026-08-18T07:29:47Z")

</div>

Hello, I am seeing the prebuilt rule Multiple Machine Learning Alerts by Influencer Field fail with: verification\_exception Unknown column \[job\_id\] Unknown column \[influencers.influencer\_field\_name\] Unknown column \[inf…

---

## [Managing Ammunition Link Inventory Data with Search and Analytics Systems](https://discuss.elastic.co/t/managing-ammunition-link-inventory-data-with-search-and-analytics-systems/387712)

<div class="topic-metadata">

**Author:** [@gamerlook](https://discuss.elastic.co/u/gamerlook)\
**Replies:** 0\
**Last updated:** [July 7, 2026, 2:03pm UTC](https://discuss.elastic.co/t/managing-ammunition-link-inventory-data-with-search-and-analytics-systems/387712 "2026-07-07T14:03:56Z")

</div>

Hello everyone, I am exploring how large technical inventories can be organized and searched efficiently using modern data platforms. In industries where components such as ammunition links, connectors, or mechanical pa…

---

## [Feedback on the Security Solution Dashboard Experience](https://discuss.elastic.co/t/feedback-on-the-security-solution-dashboard-experience/386721)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [June 15, 2026, 8:25am UTC](https://discuss.elastic.co/t/feedback-on-the-security-solution-dashboard-experience/386721 "2026-06-15T08:25:50Z")

</div>

Hello, I would like to share some feedback regarding the Security Solution dashboard experience in Kibana. While I appreciate the effort to provide a dedicated Security-focused dashboard experience, many users in our en…

---

## [No response from Sales for Student License (Self-Managed )](https://discuss.elastic.co/t/no-response-from-sales-for-student-license-self-managed/386366)

<div class="topic-metadata">

**Author:** [@Borhen\_Alaya](https://discuss.elastic.co/u/Borhen_Alaya)\
**Replies:** 5\
**Last updated:** [May 19, 2026, 1:50am UTC](https://discuss.elastic.co/t/no-response-from-sales-for-student-license-self-managed/386366 "2026-05-19T01:50:12Z")

</div>

Hi everyone, I am a final-year student, working on my graduation project (Threat Detection with Elastic Security on local VMs). I need to test Email Connectors for detection rules (Platinum feature). I contacted Suppor…

---

## [Cofense Intelligence (ti integration)](https://discuss.elastic.co/t/cofense-intelligence-ti-integration/386065)

<div class="topic-metadata">

**Author:** [@walburton](https://discuss.elastic.co/u/walburton)\
**Replies:** 0\
**Last updated:** [April 27, 2026, 9:39pm UTC](https://discuss.elastic.co/t/cofense-intelligence-ti-integration/386065 "2026-04-27T21:39:25Z")

</div>

Creating this thread to request support for the Cofense Intelligence v2 (ThreatHQ) API which would provide the ability to natively pull Threat Intel from the Cofense feed into the Elastic TI product. This currently is no…

---

## [Refer to value lists in ES|QL?](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135)

<div class="topic-metadata">

**Author:** [@alyx](https://discuss.elastic.co/u/alyx)\
**Replies:** 1\
**Last updated:** [April 17, 2026, 6:37pm UTC](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135 "2026-04-17T18:37:21Z")

</div>

Hi everyone! Trying to migrate from other SIEM platforms. One question is, is it possible to define some lists and refer to them across different rules? Like WHERE source.ip IN ${some\_defined\_list}? I tried to use valu…

---

## [Error after creating Detection rules in Elastic Security; Not getting alerts](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908)

<div class="topic-metadata">

**Author:** [@wicklanm](https://discuss.elastic.co/u/wicklanm)\
**Replies:** 3\
**Last updated:** [April 16, 2026, 7:05pm UTC](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908 "2026-04-16T19:05:02Z")

</div>

Hey everyone, After I added Security Detection Rules in my Elastic Search, I get the following error below. what does this mean and what can I do to fix it? I am not getting any alerts from this. This is for my Windows …

---

## [Using Elastic Security as SOAR for IBM QRadar SIEM (Log Forwarding Architecture)](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 5\
**Last updated:** [April 16, 2026, 1:41pm UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893 "2026-04-16T13:41:59Z")

</div>

Hi everyone, I'm working on a project to integrate IBM QRadar SIEM with Elastic Security. The goal is to use Elastic specifically for its SOAR capabilities (Case Management, Automation, Response Actions) while keeping Q…

---

## [UX improvements (Security app)](https://discuss.elastic.co/t/ux-improvements-security-app/385898)

<div class="topic-metadata">

**Author:** [@proclick](https://discuss.elastic.co/u/proclick)\
**Replies:** 1\
**Last updated:** [April 16, 2026, 2:58am UTC](https://discuss.elastic.co/t/ux-improvements-security-app/385898 "2026-04-16T02:58:50Z")

</div>

Hey Team, are there planned any updates regarding security alerts managing? Will it be possible to add a Note as a bulk action for the few similar cases as it is possible to change alerts' status and closure reason now…

---

## [Workflows' Connectors in DaC](https://discuss.elastic.co/t/workflows-connectors-in-dac/385829)

<div class="topic-metadata">

**Author:** [@proclick](https://discuss.elastic.co/u/proclick)\
**Replies:** 0\
**Last updated:** [April 9, 2026, 5:43pm UTC](https://discuss.elastic.co/t/workflows-connectors-in-dac/385829 "2026-04-09T17:43:51Z")

</div>

Hello Team, I’ve been using DaC for a while in my infrastructure and pretty satisfied with it as a source of truth and version control. I’ve recently created few custom Workflows and wanted to attach them to the securi…

---

## [System requirements for Elastic Security "All-in-One" pilot deployment](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 3\
**Last updated:** [April 3, 2026, 8:30am UTC](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731 "2026-04-03T08:30:42Z")

</div>

Hello everyone, My company is planning a pilot project to test Elastic Security (including Elasticsearch, Kibana, Logstash, and Fleet). We are also looking into integrating it with various third-party services. For thi…

---

## [Elastic - MISP Integration shows total Indicators ( fortigate logs)](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132)

<div class="topic-metadata">

**Author:** [@4l13v](https://discuss.elastic.co/u/4l13v)\
**Replies:** 5\
**Last updated:** [February 24, 2026, 11:07am UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132 "2026-02-24T11:07:56Z")

</div>

Hello community. I am having big issue right now. I have Integrated Fortigate and Elastic. Then attempted to integrate MISP to Elastic. Integration was well till \[Logs MISP\] Dashboard was thinking Total Indicators coun…

---

## [Elastic Rule Alert With External hyper link field creation in highlighted Fields \[feature request\]](https://discuss.elastic.co/t/elastic-rule-alert-with-external-hyper-link-field-creation-in-highlighted-fields-feature-request/384868)

<div class="topic-metadata">

**Author:** [@welch27330](https://discuss.elastic.co/u/welch27330)\
**Replies:** 2\
**Last updated:** [February 13, 2026, 2:34am UTC](https://discuss.elastic.co/t/elastic-rule-alert-with-external-hyper-link-field-creation-in-highlighted-fields-feature-request/384868 "2026-02-13T02:34:30Z")

</div>

Is there a way to construct a URL that will render as a hyper link in the alerts dashboard that will allow the user to review (Highlighted fields) the alert and then show a hyperlink to the external asset that the inform…

---

## [Exceptions in rules through DaC](https://discuss.elastic.co/t/exceptions-in-rules-through-dac/384790)

<div class="topic-metadata">

**Author:** [@proclick](https://discuss.elastic.co/u/proclick)\
**Replies:** 2\
**Last updated:** [February 9, 2026, 9:43pm UTC](https://discuss.elastic.co/t/exceptions-in-rules-through-dac/384790 "2026-02-09T21:43:35Z")

</div>

Greetings, I am not sure that I use right category so I am sorry in advance. Is it possible to add exceptions to the rule using Detection as Code from Elastic directly in the rule file (.toml) without creating a Shared…

---

## [\[Custom API\] Integration via GUI](https://discuss.elastic.co/t/custom-api-integration-via-gui/384707)

<div class="topic-metadata">

**Author:** [@kulisiber](https://discuss.elastic.co/u/kulisiber)\
**Replies:** 0\
**Last updated:** [January 23, 2026, 8:50am UTC](https://discuss.elastic.co/t/custom-api-integration-via-gui/384707 "2026-01-23T08:50:37Z")

</div>

Hello community team, I am a newbie in elastic, and now I used elastic for security for SIEM in my company. I am confused to setting Custom Integration - Custom API via GUI, can you give me some example for format data…

---

## [What Can I Do with Elastic SIEM Free Tier? (Capabilities and Limitations)](https://discuss.elastic.co/t/what-can-i-do-with-elastic-siem-free-tier-capabilities-and-limitations/383103)

<div class="topic-metadata">

**Author:** [@cyberfury](https://discuss.elastic.co/u/cyberfury)\
**Replies:** 1\
**Last updated:** [October 30, 2025, 2:01pm UTC](https://discuss.elastic.co/t/what-can-i-do-with-elastic-siem-free-tier-capabilities-and-limitations/383103 "2025-10-30T14:01:42Z")

</div>

Hi everyone, I’ve successfully installed on premises Elasticsearch, Logstash, Kibana, and Elastic Agent/Fleet Server on my Ubuntu server. I’m now exploring the SIEM features in the Elastic Stack free tier, but I’m a bit…

---

## [Fleet server, policy, and integrations for Linux terminal](https://discuss.elastic.co/t/fleet-server-policy-and-integrations-for-linux-terminal/382981)

<div class="topic-metadata">

**Author:** [@Eren\_Cil](https://discuss.elastic.co/u/Eren_Cil)\
**Replies:** 6\
**Last updated:** [October 28, 2025, 1:20pm UTC](https://discuss.elastic.co/t/fleet-server-policy-and-integrations-for-linux-terminal/382981 "2025-10-28T13:20:54Z")

</div>

Hello everyone. I want to watch my Linux terminal with simple integrations and custom-defined rules. Right now, I’ve tried system, auditd, or both at the same time. But there is always something wrong with the fleet serv…

---

## [Integration of Kaspersky AV with the elastic SIEM](https://discuss.elastic.co/t/integration-of-kaspersky-av-with-the-elastic-siem/358924)

<div class="topic-metadata">

**Author:** [@Amanda\_Riverol\_Quesa](https://discuss.elastic.co/u/Amanda_Riverol_Quesa)\
**Replies:** 4\
**Last updated:** [October 26, 2025, 8:28am UTC](https://discuss.elastic.co/t/integration-of-kaspersky-av-with-the-elastic-siem/358924 "2025-10-26T08:28:53Z")

</div>

I would like to send the Kaspersky antivirus events to the elastic stack but I can't find an integration that allows me to do that. Is there a way to do it?

---

## [TypeError: t is not a function](https://discuss.elastic.co/t/typeerror-t-is-not-a-function/382294)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 1\
**Last updated:** [October 3, 2025, 8:50pm UTC](https://discuss.elastic.co/t/typeerror-t-is-not-a-function/382294 "2025-10-03T20:50:10Z")

</div>

When I receive an email alert, it contains a hyperlink that is supposed to take me to the details of the email alert, but when I open the message, I get this error message. Error details

---

## [Elastic Security Threat Match rule](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 5\
**Last updated:** [October 1, 2025, 9:30am UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281 "2025-10-01T09:30:09Z")

</div>

I have a couple of questions about how threat match rules work in Elasticsearch, which I feel the documentation does not cover very well. The question is about the Custom query parameter, the frequency, and the addition…

---

## [O365 Logs - Single failed log in attempt multiple logs generated](https://discuss.elastic.co/t/o365-logs-single-failed-log-in-attempt-multiple-logs-generated/382237)

<div class="topic-metadata">

**Author:** [@rey\_espinosa](https://discuss.elastic.co/u/rey_espinosa)\
**Replies:** 2\
**Last updated:** [September 29, 2025, 6:35am UTC](https://discuss.elastic.co/t/o365-logs-single-failed-log-in-attempt-multiple-logs-generated/382237 "2025-09-29T06:35:51Z")

</div>

Is it possible that a single failed log in attempt can generate multiple logs and the only difference it a millisecond on their timestamp that looks like automated attack ?

---

## [Missing md5 field in Harmony Email & Collaboration integration with Elastic](https://discuss.elastic.co/t/missing-md5-field-in-harmony-email-collaboration-integration-with-elastic/380401)

<div class="topic-metadata">

**Author:** [@jares](https://discuss.elastic.co/u/jares)\
**Replies:** 1\
**Last updated:** [August 19, 2025, 12:06am UTC](https://discuss.elastic.co/t/missing-md5-field-in-harmony-email-collaboration-integration-with-elastic/380401 "2025-08-19T00:06:48Z")

</div>

We are currently using the Checkpoint Harmony Email & Collaboration integration to forward logs to our ELK stack. However, we have noticed that the md5 field—which contains the hash values of email attachments—is missing…

---

## [Fortigate not listed under "Network events" in Security](https://discuss.elastic.co/t/fortigate-not-listed-under-network-events-in-security/379754)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 3\
**Last updated:** [July 24, 2025, 10:57am UTC](https://discuss.elastic.co/t/fortigate-not-listed-under-network-events-in-security/379754 "2025-07-24T10:57:16Z")

</div>

Hi, I'm wondering why Fortigate is not listed under the "Network events" pane in Security overview dashboard? Including screenshot for reference. Fortigate is an integration available to add, so I think it should be l…

---

## [Elastic and AlienVault OTX integration](https://discuss.elastic.co/t/elastic-and-alienvault-otx-integration/380376)

<div class="topic-metadata">

**Author:** [@Vishag\_Learning](https://discuss.elastic.co/u/Vishag_Learning)\
**Replies:** 1\
**Last updated:** [July 24, 2025, 5:20am UTC](https://discuss.elastic.co/t/elastic-and-alienvault-otx-integration/380376 "2025-07-24T05:20:47Z")

</div>

I'm integrating OTX TI with Elastic security. I used API from AlienVault OTX. BUt it asking for installing agent. Where to install it? How to proceed with it in right way ? Anyone Please help me with your insights on th…

---

## [Maximum Number of Cases Template on Elastic SIEM](https://discuss.elastic.co/t/maximum-number-of-cases-template-on-elastic-siem/380248)

<div class="topic-metadata">

**Author:** [@rusadirr](https://discuss.elastic.co/u/rusadirr)\
**Replies:** 2\
**Last updated:** [July 24, 2025, 3:52am UTC](https://discuss.elastic.co/t/maximum-number-of-cases-template-on-elastic-siem/380248 "2025-07-24T03:52:34Z")

</div>

On Security \> Cases \> Settings. I've reached the maximum number of templates (10 templates). This templates used to help case creation process more faster by auto-fill several input. Can I increase the maximum number of…

---

## [Is there a way to correlate FortiGate logs?](https://discuss.elastic.co/t/is-there-a-way-to-correlate-fortigate-logs/380143)

<div class="topic-metadata">

**Author:** [@meatwad](https://discuss.elastic.co/u/meatwad)\
**Replies:** 1\
**Last updated:** [July 20, 2025, 10:39pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-correlate-fortigate-logs/380143 "2025-07-20T22:39:00Z")

</div>

Hi there, I'm ingesting logs from our Fortinet FortiGate VPN server and was wondering if there's a way to correlate login sessions. The issue I'm trying to solve for is that the logs that show a successful login don't …

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=1)
