# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=10

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 11

---

## [Alerts dont match time on server](https://discuss.elastic.co/t/alerts-dont-match-time-on-server/281604)

<div class="topic-metadata">

**Author:** [@nwenner76](https://discuss.elastic.co/u/nwenner76)\
**Replies:** 2\
**Last updated:** [August 20, 2021, 9:49pm UTC](https://discuss.elastic.co/t/alerts-dont-match-time-on-server/281604 "2021-08-20T21:49:03Z")

</div>

Running Wazuh 7.10.02. Host, Wazuh, and Kibana show the right time, but when I get the alerts in my email, the body of the email shows the wrong time. Setup is all on the same server. All systems are in the same office…

---

## [Detection Rules don't alert](https://discuss.elastic.co/t/detection-rules-dont-alert/280736)

<div class="topic-metadata">

**Author:** [@omlette](https://discuss.elastic.co/u/omlette)\
**Replies:** 4\
**Last updated:** [August 13, 2021, 8:41pm UTC](https://discuss.elastic.co/t/detection-rules-dont-alert/280736 "2021-08-13T20:41:53Z")

</div>

I'm setting up detection rules, so I wanted to start small and verify that the workflows was functioning, so I've enabled the Whoami Process Activity. I've run the whoami command several times over the last several hours…

---

## [Elastic SIEM TheHive Integration](https://discuss.elastic.co/t/elastic-siem-thehive-integration/279729)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [August 10, 2021, 12:52pm UTC](https://discuss.elastic.co/t/elastic-siem-thehive-integration/279729 "2021-08-10T12:52:20Z")

</div>

Hello, Is there any plan to integrate more SIEM Case connectors, for example for TheHive? Willem

---

## [Default DIsable Alert Sync for new Cases](https://discuss.elastic.co/t/default-disable-alert-sync-for-new-cases/279777)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [August 5, 2021, 8:26am UTC](https://discuss.elastic.co/t/default-disable-alert-sync-for-new-cases/279777 "2021-08-05T08:26:52Z")

</div>

Hello, Can we set the "Sync alerts" option for new cases default to 'off' or disabled? Tried it and it doesn't make a lot of sense for me. Setting a case to "In Progress" does not seem to set the related timeline alerts…

---

## [Threshold Rule type - not able to send more than three field values in email action](https://discuss.elastic.co/t/threshold-rule-type-not-able-to-send-more-than-three-field-values-in-email-action/280309)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 0\
**Last updated:** [August 3, 2021, 12:38pm UTC](https://discuss.elastic.co/t/threshold-rule-type-not-able-to-send-more-than-three-field-values-in-email-action/280309 "2021-08-03T12:38:53Z")

</div>

Hi, Threshold rule type is not allowing to send more than three field values in email action body. Group by is allowed to do onyl for three fields and those field values are only are available in the aggregated alert ou…

---

## [SIEM Webhook](https://discuss.elastic.co/t/siem-webhook/280466)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 0\
**Last updated:** [August 4, 2021, 6:43pm UTC](https://discuss.elastic.co/t/siem-webhook/280466 "2021-08-04T18:43:36Z")

</div>

How do i compose the webhook to pull the SIEM data ? , none of the prepopulated fields work

---

## [Elastic Entreprise SIEM question](https://discuss.elastic.co/t/elastic-entreprise-siem-question/280392)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 2\
**Last updated:** [August 4, 2021, 11:58am UTC](https://discuss.elastic.co/t/elastic-entreprise-siem-question/280392 "2021-08-04T11:58:33Z")

</div>

Hello, So in my company we want to make one SIEM for our clients, and we want to make them all in one cluster as they are small comapnies and don't generate a lot of logs / day. I would like to know if there is a poss…

---

## [Wrong hosts last event elastic siem](https://discuss.elastic.co/t/wrong-hosts-last-event-elastic-siem/280176)

<div class="topic-metadata">

**Author:** [@artsius](https://discuss.elastic.co/u/artsius)\
**Replies:** 0\
**Last updated:** [August 2, 2021, 3:32am UTC](https://discuss.elastic.co/t/wrong-hosts-last-event-elastic-siem/280176 "2021-08-02T03:32:48Z")

</div>

I've some problem with last event in my elastic siem environment. The date is incorrect and I don't know how to fix this. could anyone give the suggests on this? I'm still new on Elasticsearch.

---

## [How do you specify the "forbidden hours" in the Detection Rule "Auditd Login Attempt at Forbidden Time"](https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713)

<div class="topic-metadata">

**Author:** [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Replies:** 2\
**Last updated:** [July 28, 2021, 11:29am UTC](https://discuss.elastic.co/t/how-do-you-specify-the-forbidden-hours-in-the-detection-rule-auditd-login-attempt-at-forbidden-time/279713 "2021-07-28T11:29:30Z")

</div>

I came across that Detection Rule but it seems unusual to me that i cannot specify the "Forbidden Times" somehow. My guess is that auditd has that event that can be triggered but the thing is that somehow you can control…

---

## [Difference between (event.module: system - event.action: user\_login) AND (event.module: auditd - event.action: logged-in)](https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712)

<div class="topic-metadata">

**Author:** [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Replies:** 2\
**Last updated:** [July 27, 2021, 4:03pm UTC](https://discuss.elastic.co/t/difference-between-event-module-system-event-action-user-login-and-event-module-auditd-event-action-logged-in/279712 "2021-07-27T16:03:48Z")

</div>

I have set on a host both packetbeat and auditbeat. I wanted to set a rule about login events but it confuses me a bit the separation between event.module: system and event.module: auditd. At the SIEM overview there is …

---

## [ElasticSIEM unable to find \[logs-endpoint.alerts](https://discuss.elastic.co/t/elasticsiem-unable-to-find-logs-endpoint-alerts/277681)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 11\
**Last updated:** [July 21, 2021, 1:20pm UTC](https://discuss.elastic.co/t/elasticsiem-unable-to-find-logs-endpoint-alerts/277681 "2021-07-21T13:20:49Z")

</div>

I have been able to start using the elastic SIEM recently, and am having the following message show up in my Kibana, both in the UI as well as in the command line when I start the service. \</\> log \[15:02:19.220\] \[erro…

---

## [Assign Single Exception to Multiple Detection Rules](https://discuss.elastic.co/t/assign-single-exception-to-multiple-detection-rules/278930)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [July 16, 2021, 8:38pm UTC](https://discuss.elastic.co/t/assign-single-exception-to-multiple-detection-rules/278930 "2021-07-16T20:38:00Z")

</div>

Hi All, I currently have a use-case where I have a few rules that looks at similar data, but are intended to detect different things. These rules have a very similar set of exceptions assigned to them. I'd like to be a…

---

## [Cases as Metrics](https://discuss.elastic.co/t/cases-as-metrics/278545)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [July 13, 2021, 1:20pm UTC](https://discuss.elastic.co/t/cases-as-metrics/278545 "2021-07-13T13:20:07Z")

</div>

Hi All, I was wondering if anyone has any ideas for how to use cases within Elastic security for gathering/reporting metrics? I'm looking for collecting metrics like, mean time to detection, mean time to mitigation, me…

---

## [Auditing all Linux clients with centralised server](https://discuss.elastic.co/t/auditing-all-linux-clients-with-centralised-server/278246)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 3\
**Last updated:** [July 10, 2021, 5:39pm UTC](https://discuss.elastic.co/t/auditing-all-linux-clients-with-centralised-server/278246 "2021-07-10T17:39:32Z")

</div>

Hi, I have 20 Linux servers in the network. Is there a way to audit all Linux clients using a centralized server? For example, what commands are run by John on Linuxnode1? Steve on Linuxnode15? and so on and so forth to…

---

## [Retrieve Documents in Threshold Signal](https://discuss.elastic.co/t/retrieve-documents-in-threshold-signal/274913)

<div class="topic-metadata">

**Author:** [@Amorik](https://discuss.elastic.co/u/Amorik)\
**Replies:** 5\
**Last updated:** [July 6, 2021, 2:54pm UTC](https://discuss.elastic.co/t/retrieve-documents-in-threshold-signal/274913 "2021-07-06T14:54:44Z")

</div>

When a signal is created it it contains a series of fields representing what i assume to be information regarding what triggered the rule. In particular is the signal.parent.\* fields (also signal.parents.\* - not that i u…

---

## [Detection Rule with query issues](https://discuss.elastic.co/t/detection-rule-with-query-issues/277706)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 4\
**Last updated:** [July 6, 2021, 7:24am UTC](https://discuss.elastic.co/t/detection-rule-with-query-issues/277706 "2021-07-06T07:24:26Z")

</div>

Hi All, I've made a custom detection rule to detect windows defender events related to malware or stop based on the below documentation: The query is as bellow: winlog.event\_id: "1002" or "1003" or "1005" or "1006" …

---

## [Authentications zero successes - SIEM](https://discuss.elastic.co/t/authentications-zero-successes-siem/276707)

<div class="topic-metadata">

**Author:** [@fabinho1314](https://discuss.elastic.co/u/fabinho1314)\
**Replies:** 2\
**Last updated:** [July 1, 2021, 3:25pm UTC](https://discuss.elastic.co/t/authentications-zero-successes-siem/276707 "2021-07-01T15:25:02Z")

</div>

Hi there, I deployed with azure the solution "Elasticsearch (Self-Managed)" and im getting an odd error. When i go to the SIEM part \> Hosts \> Authentications, it only returns fails and zero successes as per the image b…

---

## [Unusual Process For a Windows Host (rare\_process\_by\_host\_windows\_ecs)](https://discuss.elastic.co/t/unusual-process-for-a-windows-host-rare-process-by-host-windows-ecs/277078)

<div class="topic-metadata">

**Author:** [@ARDiver86](https://discuss.elastic.co/u/ARDiver86)\
**Replies:** 4\
**Last updated:** [July 1, 2021, 8:18am UTC](https://discuss.elastic.co/t/unusual-process-for-a-windows-host-rare-process-by-host-windows-ecs/277078 "2021-07-01T08:18:23Z")

</div>

This job appears to be looking at a list of process create events to determine if a process is new or existed previously. The issue I think we are having is it is alerting us on a lot of processes that existed previously…

---

## [Using "message" in custom alert rule](https://discuss.elastic.co/t/using-message-in-custom-alert-rule/275899)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 2\
**Last updated:** [June 25, 2021, 12:51pm UTC](https://discuss.elastic.co/t/using-message-in-custom-alert-rule/275899 "2021-06-25T12:51:31Z")

</div>

I would like to create an alert that follows: "message: some search string" When I create the alert and save it. I receive the following error "Bulk Indexing of signals failed: object mapping for \[source\] tried to par…

---

## [ThreatIntel + module configuration](https://discuss.elastic.co/t/threatintel-module-configuration/276652)

<div class="topic-metadata">

**Author:** [@malvivent7](https://discuss.elastic.co/u/malvivent7)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 10:18am UTC](https://discuss.elastic.co/t/threatintel-module-configuration/276652 "2021-06-25T10:18:18Z")

</div>

Hi to all, i have enabled through filebeat modules the threatintel module and after that i have configured threatintel.yml activating otx and abusemalware than filebeat -e setup . So far so good but till now i dont see …

---

## [Threat detection rules VS beats](https://discuss.elastic.co/t/threat-detection-rules-vs-beats/275311)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 10:26am UTC](https://discuss.elastic.co/t/threat-detection-rules-vs-beats/275311 "2021-06-25T10:26:30Z")

</div>

Can someone tell me if default detection rules are capable of triggering alerts base on logs from events (not from fleet). I.e. new user creation. I can not make it work. Also, how do I define my own custom policies that…

---

## [Creating an email connector](https://discuss.elastic.co/t/creating-an-email-connector/275904)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 4\
**Last updated:** [June 23, 2021, 6:06pm UTC](https://discuss.elastic.co/t/creating-an-email-connector/275904 "2021-06-23T18:06:33Z")

</div>

What exactly needs to be created for this action ? I am reviewing the documentation listed here: Email connector and action | Kibana Guide \[7.13\] | Elastic.

---

## [{{#context.alerts}} not showing up in markdown](https://discuss.elastic.co/t/context-alerts-not-showing-up-in-markdown/276177)

<div class="topic-metadata">

**Author:** [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Replies:** 2\
**Last updated:** [June 16, 2021, 8:11pm UTC](https://discuss.elastic.co/t/context-alerts-not-showing-up-in-markdown/276177 "2021-06-16T20:11:24Z")

</div>

I am trying to create a simple notification based off of the post described here: {{#context.alerts}} - \*Beat Name\*: {noformat}{{beat.name}}{noformat} {{/context.alerts}} However, the context.alerts block is not get…

---

## [Detections - Kibana](https://discuss.elastic.co/t/detections-kibana/275716)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 7\
**Last updated:** [June 13, 2021, 7:04pm UTC](https://discuss.elastic.co/t/detections-kibana/275716 "2021-06-13T19:04:31Z")

</div>

Hi, I am trying to use detection rules in Kibana. I am testing it on predefined rules under Security module. To be exact " User Account Creation" . I am using winlog to send out data to kibana. I see user creation event…

---

## [EQL library where](https://discuss.elastic.co/t/eql-library-where/275524)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [June 12, 2021, 7:57pm UTC](https://discuss.elastic.co/t/eql-library-where/275524 "2021-06-12T19:57:22Z")

</div>

Hello, Just noticed an EQL query in Suspicious RDP ActiveX Client Loaded | Elastic Security Solution \[7.13\] | Elastic where a "library where" clause is used. What kind of events contain library? I always though the firs…

---

## [EQL cidrmatch issue](https://discuss.elastic.co/t/eql-cidrmatch-issue/274885)

<div class="topic-metadata">

**Author:** [@ima](https://discuss.elastic.co/u/ima)\
**Replies:** 3\
**Last updated:** [June 7, 2021, 1:46pm UTC](https://discuss.elastic.co/t/eql-cidrmatch-issue/274885 "2021-06-07T13:46:28Z")

</div>

hello guys, I created an eql rule for ssh access I wanna match multiple IP ranges but I get this error that the destination.ip field is text and not IP can you please suggest me another way to do that. here's my query { …

---

## [Signal Field Schema Documentation](https://discuss.elastic.co/t/signal-field-schema-documentation/274912)

<div class="topic-metadata">

**Author:** [@Amorik](https://discuss.elastic.co/u/Amorik)\
**Replies:** 0\
**Last updated:** [June 3, 2021, 7:06pm UTC](https://discuss.elastic.co/t/signal-field-schema-documentation/274912 "2021-06-03T19:06:27Z")

</div>

Detection's creates the .siem-signals index responsible for housing alerts generated by the system. While it conforms to ECS the fields under signal.\* are not documented GitHub - elastic/ecs: Elastic Common Schema. Is th…

---

## [Discover is not working for range between \<date\> - "now "](https://discuss.elastic.co/t/discover-is-not-working-for-range-between-date-now/274641)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 2\
**Last updated:** [June 3, 2021, 4:52pm UTC](https://discuss.elastic.co/t/discover-is-not-working-for-range-between-date-now/274641 "2021-06-03T16:52:22Z")

</div>

I have a strange problem. In discovery tab, if I specify time between lets say Jun 1, 2021@ 07:56:46 -\> now I get no results However if I search Jun 1, 2021@ 07:56:46 -\>Jun 1, 2021@ 10:00:46 everyth…

---

## [Elastic agent log parsing](https://discuss.elastic.co/t/elastic-agent-log-parsing/274827)

<div class="topic-metadata">

**Author:** [@Guncixx](https://discuss.elastic.co/u/Guncixx)\
**Replies:** 0\
**Last updated:** [June 3, 2021, 6:59am UTC](https://discuss.elastic.co/t/elastic-agent-log-parsing/274827 "2021-06-03T06:59:39Z")

</div>

While testing Elastic SIEM and different shippers I discovered that both filebeat and elastic agent is not parsing Ubuntu auth log completely, there are some events where user and some other fields not getting populated.…

---

## [SIEM prebuilt rules](https://discuss.elastic.co/t/siem-prebuilt-rules/274724)

<div class="topic-metadata">

**Author:** [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Replies:** 2\
**Last updated:** [June 2, 2021, 2:43pm UTC](https://discuss.elastic.co/t/siem-prebuilt-rules/274724 "2021-06-02T14:43:17Z")

</div>

Hello, I'm searching for prebuild rules for elastic SIEM, i found that i can use elastic provided rules : But i would like to know if there is any other source to get pre build rules for elastic SIEM, for example rul…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=9)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=11)
