# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=1

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 2

---

## [How to expose custom fields from alert JSON in the Slack API connector?](https://discuss.elastic.co/t/how-to-expose-custom-fields-from-alert-json-in-the-slack-api-connector/378142)

<div class="topic-metadata">

**Author:** [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Replies:** 0\
**Last updated:** [May 14, 2025, 1:48pm UTC](https://discuss.elastic.co/t/how-to-expose-custom-fields-from-alert-json-in-the-slack-api-connector/378142 "2025-05-14T13:48:40Z")

</div>

Hello Team I'm implementing detection rules in Elastic Security (Kibana v8.x) and want to notify alerts in Slack using the Slack API connector. However, I can only use the predefined variables listed in the + Add variab…

---

## [Machine learning use case - Anomaly Detection](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237)

<div class="topic-metadata">

**Author:** [@sunith](https://discuss.elastic.co/u/sunith)\
**Replies:** 6\
**Last updated:** [July 10, 2025, 11:56am UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237 "2025-07-10T11:56:54Z")

</div>

Hi Everyone, I'm currently developing and testing a Machine Learning-based use case in Elastic for anomaly detection. I've cloned and configured the ML job "auth\_rare\_hour\_for\_a\_user", which is designed to detect user l…

---

## [How to detect abnormal User behaviour (sequence of actions)](https://discuss.elastic.co/t/how-to-detect-abnormal-user-behaviour-sequence-of-actions/377964)

<div class="topic-metadata">

**Author:** [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Replies:** 3\
**Last updated:** [May 24, 2025, 4:14pm UTC](https://discuss.elastic.co/t/how-to-detect-abnormal-user-behaviour-sequence-of-actions/377964 "2025-05-24T16:14:42Z")

</div>

Hi, Need help - how to detect abnormal User behaviour (sequence of actions) using Elastic ML (or other tools)? For example - user can perform following actions: Login Read Patients List Read Patient Info Read Clinica…

---

## [Cef log with custom udp integration](https://discuss.elastic.co/t/cef-log-with-custom-udp-integration/378421)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 4\
**Last updated:** [May 22, 2025, 2:19pm UTC](https://discuss.elastic.co/t/cef-log-with-custom-udp-integration/378421 "2025-05-22T14:19:19Z")

</div>

Hi all, I am using Custom UDP integration to do CEF log ingestion. I cannot use CEF integration due to limitations of that integration. The decode\_cef processor is not available in the pipelines. What is the best way to…

---

## ['add agent' issue](https://discuss.elastic.co/t/add-agent-issue/378397)

<div class="topic-metadata">

**Author:** [@ASahinkayasi](https://discuss.elastic.co/u/ASahinkayasi)\
**Replies:** 0\
**Last updated:** [May 21, 2025, 10:02pm UTC](https://discuss.elastic.co/t/add-agent-issue/378397 "2025-05-21T22:02:42Z")

</div>

Hi, I'm following the Elastic Security for SIEM (On-Demand) course. I'm still at the beginning of the course and I'm stuck on 'add agent' in Fleet. The system gives the error in the image. Does anyone have any idea how I…

---

## [Enriching Web Filter Logs with Username from Traffic Logs Using Session ID in Fortinet Logs](https://discuss.elastic.co/t/enriching-web-filter-logs-with-username-from-traffic-logs-using-session-id-in-fortinet-logs/377978)

<div class="topic-metadata">

**Author:** [@Johan\_Alda](https://discuss.elastic.co/u/Johan_Alda)\
**Replies:** 0\
**Last updated:** [May 9, 2025, 6:07am UTC](https://discuss.elastic.co/t/enriching-web-filter-logs-with-username-from-traffic-logs-using-session-id-in-fortinet-logs/377978 "2025-05-09T06:07:29Z")

</div>

Title: How to Enrich Fortinet UTM Web Filter Logs with Username from Traffic Logs Using Session ID? Body: Hi everyone, I'm working on a detection use case using Fortinet logs ingested into Elasticsearch. Objective: I …

---

## [Import ingest pipeline](https://discuss.elastic.co/t/import-ingest-pipeline/377843)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 1\
**Last updated:** [May 6, 2025, 12:12pm UTC](https://discuss.elastic.co/t/import-ingest-pipeline/377843 "2025-05-06T12:12:03Z")

</div>

Hi all, how can i import a complex custom ingestion pipeline from one elastic to another? I tried with the 'Import processors' button but after loading the json containing the processors array and pressing the 'Load and…

---

## [Error in detection rule: Remote Computer Account DnsHostName Update](https://discuss.elastic.co/t/error-in-detection-rule-remote-computer-account-dnshostname-update/377772)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 8\
**Last updated:** [May 3, 2025, 7:12pm UTC](https://discuss.elastic.co/t/error-in-detection-rule-remote-computer-account-dnshostname-update/377772 "2025-05-03T19:12:11Z")

</div>

I have an issue with a detection rule. Seems like there's a type mismatch in tables. Is this something i could fix myself or should this be handled by dev? { "@timestamp": \[ "2025-05-03T08:36:23.495Z" \], "ecs.…

---

## [Wrong ML Job query packetbeat\_rare\_user\_agent or missing event.dataset in network traffic data?](https://discuss.elastic.co/t/wrong-ml-job-query-packetbeat-rare-user-agent-or-missing-event-dataset-in-network-traffic-data/377283)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [April 29, 2025, 6:56pm UTC](https://discuss.elastic.co/t/wrong-ml-job-query-packetbeat-rare-user-agent-or-missing-event-dataset-in-network-traffic-data/377283 "2025-04-29T18:56:15Z")

</div>

Hello, The query of the managed machine learning job packetbeat\_rare\_user\_agent doesn't match with any documents. It seems like event.dataset is not in the logs-network\_traffic.http-\* datastream? {"bool":{"filter":\[{"t…

---

## [Machine Learning Detected a Suspicious Windows Event with a High Malicious Probability Score triggering on all kinds of normal processes](https://discuss.elastic.co/t/machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score-triggering-on-all-kinds-of-normal-processes/377523)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [April 25, 2025, 2:38pm UTC](https://discuss.elastic.co/t/machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score-triggering-on-all-kinds-of-normal-processes/377523 "2025-04-25T14:38:17Z")

</div>

Hello, I activated "Machine Learning Detected a Suspicious Windows Event with a High Malicious Probability Score" and "Living off the Land Attack Detection" and followed the procedure. It seems to be triggering on a l…

---

## [Firewall logs to different Datastream by type](https://discuss.elastic.co/t/firewall-logs-to-different-datastream-by-type/377211)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 22\
**Last updated:** [April 24, 2025, 12:57pm UTC](https://discuss.elastic.co/t/firewall-logs-to-different-datastream-by-type/377211 "2025-04-24T12:57:39Z")

</div>

I am using the integration “Fortinet FortiGate Firewall Logs”. To date it is working correctly, but I have been asked to ingest the UTM type logs in a different Datastream and I really have no idea how to do this using …

---

## [Security Case Management Based on Parent Tenant & Subsidiary](https://discuss.elastic.co/t/security-case-management-based-on-parent-tenant-subsidiary/377471)

<div class="topic-metadata">

**Author:** [@kulisiber](https://discuss.elastic.co/u/kulisiber)\
**Replies:** 0\
**Last updated:** [April 24, 2025, 2:37am UTC](https://discuss.elastic.co/t/security-case-management-based-on-parent-tenant-subsidiary/377471 "2025-04-24T02:37:08Z")

</div>

Hi everyone, I have a case like the following, I monitor the parent company as well as the subsidiary. I've created 2 different tenants. What if I want to display all the cases that are made specifically from the "Secur…

---

## [CEF integration gives error if it encounters non-UTF-8 valuestion](https://discuss.elastic.co/t/cef-integration-gives-error-if-it-encounters-non-utf-8-valuestion/377193)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 0\
**Last updated:** [April 16, 2025, 12:41pm UTC](https://discuss.elastic.co/t/cef-integration-gives-error-if-it-encounters-non-utf-8-valuestion/377193 "2025-04-16T12:41:02Z")

</div>

Hi, CEF integration gives error if it encounters non-UTF-8 values. What alternatives do I have? Change the integration type? How can I at least prevent the error.message field from being populated when there are non-UTF…

---

## [Does Common Event Format (CEF) not allow a custom ingestion pipeline?](https://discuss.elastic.co/t/does-common-event-format-cef-not-allow-a-custom-ingestion-pipeline/377009)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 4\
**Last updated:** [April 11, 2025, 4:18pm UTC](https://discuss.elastic.co/t/does-common-event-format-cef-not-allow-a-custom-ingestion-pipeline/377009 "2025-04-11T16:18:24Z")

</div>

Hi, CEF integration does not allow to add a custom ingestion policy? Is this correct?

---

## [Elastic SIEM Alert hostname missing](https://discuss.elastic.co/t/elastic-siem-alert-hostname-missing/376858)

<div class="topic-metadata">

**Author:** [@axvfvv79zcx57xv7k](https://discuss.elastic.co/u/axvfvv79zcx57xv7k)\
**Replies:** 0\
**Last updated:** [April 7, 2025, 10:09am UTC](https://discuss.elastic.co/t/elastic-siem-alert-hostname-missing/376858 "2025-04-07T10:09:16Z")

</div>

Hello, I'm currently using Elastic SIEM and trying to troubleshoot an issue regarding some detection rules. For several rules — for example, "Unusual File Transfer Utility Launched" (which monitors tools like rsync, scp…

---

## [EQL Detection Rule issues](https://discuss.elastic.co/t/eql-detection-rule-issues/376641)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 1\
**Last updated:** [April 4, 2025, 5:21pm UTC](https://discuss.elastic.co/t/eql-detection-rule-issues/376641 "2025-04-04T17:21:19Z")

</div>

Hi, So i'm having some issues with my EQL detection rules. One of the use cases im running with is a possible BF attempt on a windows host. I currently have the following EQL in place which returns results fine in timel…

---

## [Closing an alert in Elastic Security without using the GUI](https://discuss.elastic.co/t/closing-an-alert-in-elastic-security-without-using-the-gui/376313)

<div class="topic-metadata">

**Author:** [@cyberm](https://discuss.elastic.co/u/cyberm)\
**Replies:** 0\
**Last updated:** [March 24, 2025, 10:50am UTC](https://discuss.elastic.co/t/closing-an-alert-in-elastic-security-without-using-the-gui/376313 "2025-03-24T10:50:37Z")

</div>

Hi everyone, I’m looking for the best strategy to close an alert in Elastic Security from an external source, without using the Kibana GUI. I’ve considered using the APIs, but I’d like to understand the best practices r…

---

## [ML anomaly detection alert](https://discuss.elastic.co/t/ml-anomaly-detection-alert/376374)

<div class="topic-metadata">

**Author:** [@sunith](https://discuss.elastic.co/u/sunith)\
**Replies:** 0\
**Last updated:** [March 25, 2025, 10:36am UTC](https://discuss.elastic.co/t/ml-anomaly-detection-alert/376374 "2025-03-25T10:36:44Z")

</div>

Hello, Could anyone please help me with this? I am working on machine learning-based anomaly detection use cases using Elastic’s built-in anomaly detection job, "auth\_rare\_hour\_for\_a\_user". I integrated this job into a…

---

## [Create new Event Renderers](https://discuss.elastic.co/t/create-new-event-renderers/375137)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 1\
**Last updated:** [March 6, 2025, 8:08am UTC](https://discuss.elastic.co/t/create-new-event-renderers/375137 "2025-03-06T08:08:09Z")

</div>

This is basically a copy from an existing, old discuss topic. Is there any progress on allowing us to modify or create our own event renders? The original topic: Is there an issue on github for this Feature Request t…

---

## [After upgrading Elastic SIEM to version 8.17.2 a lot security alerts are not being displayed.](https://discuss.elastic.co/t/after-upgrading-elastic-siem-to-version-8-17-2-a-lot-security-alerts-are-not-being-displayed/375145)

<div class="topic-metadata">

**Author:** [@nma2025](https://discuss.elastic.co/u/nma2025)\
**Replies:** 0\
**Last updated:** [February 27, 2025, 10:09am UTC](https://discuss.elastic.co/t/after-upgrading-elastic-siem-to-version-8-17-2-a-lot-security-alerts-are-not-being-displayed/375145 "2025-02-27T10:09:13Z")

</div>

After upgrading Elastic SIEM to version 8.17.2, some security alerts, such as low-severity alerts, can be verified within their respective detection rules but do not appear in the alert view.

---

## [Sysmon registry logs don't get to elastic](https://discuss.elastic.co/t/sysmon-registry-logs-dont-get-to-elastic/374772)

<div class="topic-metadata">

**Author:** [@pok\_lehbim](https://discuss.elastic.co/u/pok_lehbim)\
**Replies:** 0\
**Last updated:** [February 19, 2025, 1:53pm UTC](https://discuss.elastic.co/t/sysmon-registry-logs-dont-get-to-elastic/374772 "2025-02-19T13:53:36Z")

</div>

I'm trying to set up the detection rule called "Privilege Escalation via Windir Environment Variable" but the data that this rule relies upon isn't getting to elastic. I've made sure to have everything set up correctly, …

---

## [How to reduce false/positives for prebuilt Windows Security ML jobs?](https://discuss.elastic.co/t/how-to-reduce-false-positives-for-prebuilt-windows-security-ml-jobs/374532)

<div class="topic-metadata">

**Author:** [@Rorb](https://discuss.elastic.co/u/Rorb)\
**Replies:** 0\
**Last updated:** [February 14, 2025, 12:43am UTC](https://discuss.elastic.co/t/how-to-reduce-false-positives-for-prebuilt-windows-security-ml-jobs/374532 "2025-02-14T00:43:49Z")

</div>

Hello, I've been running Elastic Clouds prebuilt machine learning jobs for Windows Security for about a month now and I've found they create a lot of noise. About 99% of the alerts I get out of these ML jobs I end up clo…

---

## [How to Retrieve More Than 10K Records in EQL (\_eql/search)? (Elasticsearch 7.10.1)](https://discuss.elastic.co/t/how-to-retrieve-more-than-10k-records-in-eql-eql-search-elasticsearch-7-10-1/374264)

<div class="topic-metadata">

**Author:** [@Gkayy](https://discuss.elastic.co/u/Gkayy)\
**Replies:** 1\
**Last updated:** [February 11, 2025, 4:21pm UTC](https://discuss.elastic.co/t/how-to-retrieve-more-than-10k-records-in-eql-eql-search-elasticsearch-7-10-1/374264 "2025-02-11T16:21:18Z")

</div>

There is a limitation on Elastic search when doing a search for over 10k+ records, is there a way to retrieve records over 10k+? Note that I am using EQL query to retrieve records over endpoint \_EQL, I am aware that pagi…

---

## [Issue with Elastic Agent Imperva Integration](https://discuss.elastic.co/t/issue-with-elastic-agent-imperva-integration/374357)

<div class="topic-metadata">

**Author:** [@cyberm](https://discuss.elastic.co/u/cyberm)\
**Replies:** 0\
**Last updated:** [February 11, 2025, 11:26am UTC](https://discuss.elastic.co/t/issue-with-elastic-agent-imperva-integration/374357 "2025-02-11T11:26:07Z")

</div>

Hi all, We are experiencing the same issue as described in this previous post (Elastic Agent Imperva Integration , from @mgotechlock ), which was closed as unresolved. We are investigating the cause of this anomaly. Ha…

---

## [Question About the ‘Supplied Configurations’ Section in Anomaly Detection for Time Series Data with Machine Learning on Elastic Cloud 8.17](https://discuss.elastic.co/t/question-about-the-supplied-configurations-section-in-anomaly-detection-for-time-series-data-with-machine-learning-on-elastic-cloud-8-17/372340)

<div class="topic-metadata">

**Author:** [@Illya\_Bjazevic](https://discuss.elastic.co/u/Illya_Bjazevic)\
**Replies:** 4\
**Last updated:** [January 2, 2025, 9:21pm UTC](https://discuss.elastic.co/t/question-about-the-supplied-configurations-section-in-anomaly-detection-for-time-series-data-with-machine-learning-on-elastic-cloud-8-17/372340 "2025-01-02T21:21:30Z")

</div>

While using Anomaly Detection in Time Series Data with Machine Learning in Elastic Cloud 8.17, I came across the 'Supplied Configurations' section. When I clicked there, I found what is shown in the following image: …

---

## [Regarding Cross cluster replication](https://discuss.elastic.co/t/regarding-cross-cluster-replication/372349)

<div class="topic-metadata">

**Author:** [@mike123](https://discuss.elastic.co/u/mike123)\
**Replies:** 4\
**Last updated:** [December 24, 2024, 6:24pm UTC](https://discuss.elastic.co/t/regarding-cross-cluster-replication/372349 "2024-12-24T18:24:45Z")

</div>

I am having a ES cluster with Fleet server, Kibana and elastic-agents. I want to create a DR (Disaster recovery ) setup for it. I am running alerts and ML rules with Elastic Defent in this setup. If i go for bi direction…

---

## [Kibana Query Language summarize](https://discuss.elastic.co/t/kibana-query-language-summarize/370825)

<div class="topic-metadata">

**Author:** [@fitastronaut](https://discuss.elastic.co/u/fitastronaut)\
**Replies:** 4\
**Last updated:** [November 25, 2024, 3:54am UTC](https://discuss.elastic.co/t/kibana-query-language-summarize/370825 "2024-11-25T03:54:54Z")

</div>

Hello gurus, I am new with Elastic and I have been searching to no avail. I am trying to create a SIEM rule for brute force. How do I write the query for this? In Microsoft Sentinel, it will be let threshold = 5; Tabl…

---

## [Database Use case for DDL and DML command](https://discuss.elastic.co/t/database-use-case-for-ddl-and-dml-command/370843)

<div class="topic-metadata">

**Author:** [@Airtel\_Center](https://discuss.elastic.co/u/Airtel_Center)\
**Replies:** 0\
**Last updated:** [November 20, 2024, 3:18pm UTC](https://discuss.elastic.co/t/database-use-case-for-ddl-and-dml-command/370843 "2024-11-20T15:18:23Z")

</div>

Can we create use cases for below points in database. if yes can you share the use cases details Database MSSQL - Create Table Database MSSQL - Delete Table Database MSSQL - Modify Table Database MSSQL - Insert Data …

---

## [RBAC Query](https://discuss.elastic.co/t/rbac-query/370405)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 0\
**Last updated:** [November 12, 2024, 2:00pm UTC](https://discuss.elastic.co/t/rbac-query/370405 "2024-11-12T14:00:19Z")

</div>

I wish to grant some users the ability to manage security alert statuses and create cases, but i dont want them to be able to change any security rule settings. From what i can see i can only either give them full rights…

---

## [Elastic SIEM Detection Rules](https://discuss.elastic.co/t/elastic-siem-detection-rules/370390)

<div class="topic-metadata">

**Author:** [@aravindraja](https://discuss.elastic.co/u/aravindraja)\
**Replies:** 1\
**Last updated:** [November 12, 2024, 1:07pm UTC](https://discuss.elastic.co/t/elastic-siem-detection-rules/370390 "2024-11-12T13:07:51Z")

</div>

Hi Team, I have 2 windows endpoints with 2 different agent policies where in one endpoint I have integrated the system integration and in another endpoint I have integrated Windows, So in this case of SIEM detection rul…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=2)
