# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=11

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 12

---

## [Detection rule: Failed login attempts](https://discuss.elastic.co/t/detection-rule-failed-login-attempts/274590)

<div class="topic-metadata">

**Author:** [@bnk](https://discuss.elastic.co/u/bnk)\
**Replies:** 2\
**Last updated:** [June 2, 2021, 10:51am UTC](https://discuss.elastic.co/t/detection-rule-failed-login-attempts/274590 "2021-06-02T10:51:35Z")

</div>

Hi, I've created my own detection rule for employees failed login attempts. It does work but when signal comes to Security -\> Detection dashboard, it do not show user.name or host.name. This is screen shot of my rule: …

---

## [Detection rule kquery will not trigger but the query match](https://discuss.elastic.co/t/detection-rule-kquery-will-not-trigger-but-the-query-match/273085)

<div class="topic-metadata">

**Author:** [@leon3](https://discuss.elastic.co/u/leon3)\
**Replies:** 3\
**Last updated:** [May 31, 2021, 12:03pm UTC](https://discuss.elastic.co/t/detection-rule-kquery-will-not-trigger-but-the-query-match/273085 "2021-05-31T12:03:54Z")

</div>

Hi I have a weird issue when use kquery in detection rules. I use a simple query to match a field and triggering action for that but the rule will not be triggered while its query is matching in the specified interval. …

---

## [Threshold detection not working with group by](https://discuss.elastic.co/t/threshold-detection-not-working-with-group-by/274362)

<div class="topic-metadata">

**Author:** [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Replies:** 2\
**Last updated:** [May 31, 2021, 3:57am UTC](https://discuss.elastic.co/t/threshold-detection-not-working-with-group-by/274362 "2021-05-31T03:57:27Z")

</div>

Hi All, I am using Elastic version 7.12. I want to create a detection rule based on the threshold. My requirements is as follows. Identify possible Bruteforce attack coming from same source IP. If there are more than …

---

## [Detection Rule - Output of a aggregation bucket should match with other types of logs in the same index](https://discuss.elastic.co/t/detection-rule-output-of-a-aggregation-bucket-should-match-with-other-types-of-logs-in-the-same-index/274345)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 0\
**Last updated:** [May 28, 2021, 1:02pm UTC](https://discuss.elastic.co/t/detection-rule-output-of-a-aggregation-bucket-should-match-with-other-types-of-logs-in-the-same-index/274345 "2021-05-28T13:02:20Z")

</div>

Hi, Can someone please help to create a detection rule based on logic mentioned below. All unique mac.address field name with common.role:rogue should be aggregated and matched againewith the mac.address field name wit…

---

## [Timeline result of events not showing](https://discuss.elastic.co/t/timeline-result-of-events-not-showing/273930)

<div class="topic-metadata">

**Author:** [@Kupauw](https://discuss.elastic.co/u/Kupauw)\
**Replies:** 8\
**Last updated:** [May 27, 2021, 8:54pm UTC](https://discuss.elastic.co/t/timeline-result-of-events-not-showing/273930 "2021-05-27T20:54:38Z")

</div>

Hi everyone. Today i upgraded my ELK stack to 7.12.1 and everything seems to be working fine except for the SIEM timeline. I ingest logs from Cisco FTD firewalls, F5 loadbalancers and our infoblox (DHCP/DNS). When i s…

---

## [SIEM timeline cant be saved](https://discuss.elastic.co/t/siem-timeline-cant-be-saved/273963)

<div class="topic-metadata">

**Author:** [@Shubhangi](https://discuss.elastic.co/u/Shubhangi)\
**Replies:** 3\
**Last updated:** [May 25, 2021, 8:31pm UTC](https://discuss.elastic.co/t/siem-timeline-cant-be-saved/273963 "2021-05-25T20:31:38Z")

</div>

I'm using ELK v7.8 How to save SIEM timelines? The autosave feature mentioned in the blogs/doc can not be seen for me. DO I need to enable something? I'm super user with all the access

---

## [Detection Rule Key Value Reference Url's](https://discuss.elastic.co/t/detection-rule-key-value-reference-urls/272466)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 5\
**Last updated:** [May 22, 2021, 5:23pm UTC](https://discuss.elastic.co/t/detection-rule-key-value-reference-urls/272466 "2021-05-22T17:23:17Z")

</div>

Hello, After working intensively with Elastic Detections and alerting etc, I wanted to suggest that imho it would be an improvement if the reference url's were key / value instead of only the url's. Sometimes the url's …

---

## [Logstash and filebeat](https://discuss.elastic.co/t/logstash-and-filebeat/273614)

<div class="topic-metadata">

**Author:** [@Francisco\_Ramirez](https://discuss.elastic.co/u/Francisco_Ramirez)\
**Replies:** 1\
**Last updated:** [May 21, 2021, 10:52pm UTC](https://discuss.elastic.co/t/logstash-and-filebeat/273614 "2021-05-21T22:52:50Z")

</div>

Hi Folks I configured elasticsearch and kibana for visualizate event from wazuh, now i want see this event into the module siem. best regards

---

## [SIEM mail format for winevent log](https://discuss.elastic.co/t/siem-mail-format-for-winevent-log/273632)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [May 21, 2021, 7:54am UTC](https://discuss.elastic.co/t/siem-mail-format-for-winevent-log/273632 "2021-05-21T07:54:52Z")

</div>

Hi a. The mail format for elastic siem was a little weird for me at this point. For most case the mail got the right format out to me but on the case of winevent log it is a bit difference. when i try the {{winlog.eve…

---

## [Format mail send from siem detection threshold rule](https://discuss.elastic.co/t/format-mail-send-from-siem-detection-threshold-rule/273375)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 2\
**Last updated:** [May 20, 2021, 1:37am UTC](https://discuss.elastic.co/t/format-mail-send-from-siem-detection-threshold-rule/273375 "2021-05-20T01:37:34Z")

</div>

Hi all I have successfully config for siem to send alert mail and now when i tried it with the theashold rule it failed. So i want to ask how to format theashold rule mail to send infomation. The format that i tried i…

---

## [Unable to add Cisco integration under Fleet Policy](https://discuss.elastic.co/t/unable-to-add-cisco-integration-under-fleet-policy/273121)

<div class="topic-metadata">

**Author:** [@Shiv18](https://discuss.elastic.co/u/Shiv18)\
**Replies:** 1\
**Last updated:** [May 19, 2021, 3:35pm UTC](https://discuss.elastic.co/t/unable-to-add-cisco-integration-under-fleet-policy/273121 "2021-05-19T15:35:19Z")

</div>

Hi Team, I'm using Elastic agent for endpoint, servers and network devices. I can able to add policy for endpoints but for network Cisco integration alone throws me error. I'm trying to add this through Fleet policy for…

---

## [SIEM created and closed cases report](https://discuss.elastic.co/t/siem-created-and-closed-cases-report/270931)

<div class="topic-metadata">

**Author:** [@bnk](https://discuss.elastic.co/u/bnk)\
**Replies:** 9\
**Last updated:** [May 19, 2021, 9:53am UTC](https://discuss.elastic.co/t/siem-created-and-closed-cases-report/270931 "2021-05-19T09:53:21Z")

</div>

Hello, I looked information if there is a possibility to export info about created and closed cases (also tags associated with cases and other related info) in ELK SIEM, but I coudn't find any information. Is there a way…

---

## [UDP packets cover 50% of packetbeat logs](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 7\
**Last updated:** [May 18, 2021, 8:34am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689 "2021-05-18T08:34:24Z")

</div>

Hi, I can see that 50% of my packetbeat logs are from network.transport: udp . In terms of SIEM perspective do I need this types of logs in kibana? (I don't use any VOIP or streaming services on my monitored machine.) …

---

## [Threat hunting with suricata, ElasticSecurity](https://discuss.elastic.co/t/threat-hunting-with-suricata-elasticsecurity/273148)

<div class="topic-metadata">

**Author:** [@111387](https://discuss.elastic.co/u/111387)\
**Replies:** 1\
**Last updated:** [May 17, 2021, 11:51pm UTC](https://discuss.elastic.co/t/threat-hunting-with-suricata-elasticsecurity/273148 "2021-05-17T23:51:07Z")

</div>

Good morning. I have built a suricata, and I am delivering events to elasticsearch with filebeat. There are various detection rules in elasticsecurity, but among them, detection rules for suricata (ET Rule) do not exis…

---

## [Detection Rule Exceptions "is one of", comma in value](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 6\
**Last updated:** [May 12, 2021, 8:30pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738 "2021-05-12T20:30:45Z")

</div>

Hi All, I'm trying to add an exception to a detection rule. This exception is intended to be an is one of rule, that excludes a number of ISPs. However, I am running into an issue some of the ISP names contain a comma, …

---

## [Format SIEM alerts](https://discuss.elastic.co/t/format-siem-alerts/272772)

<div class="topic-metadata">

**Author:** [@vishnug](https://discuss.elastic.co/u/vishnug)\
**Replies:** 2\
**Last updated:** [May 12, 2021, 6:46pm UTC](https://discuss.elastic.co/t/format-siem-alerts/272772 "2021-05-12T18:46:50Z")

</div>

Hi, I'm using ELK v7.12.1. I have enabled few SIEM rules and configured an email action. I'm able to access the event details through {{#context.alerts}} {{.}}{{/context.alerts}}. But when sending the mail the content …

---

## [How to write a kibana rule with filename](https://discuss.elastic.co/t/how-to-write-a-kibana-rule-with-filename/272673)

<div class="topic-metadata">

**Author:** [@realtech2338](https://discuss.elastic.co/u/realtech2338)\
**Replies:** 1\
**Last updated:** [May 12, 2021, 1:14am UTC](https://discuss.elastic.co/t/how-to-write-a-kibana-rule-with-filename/272673 "2021-05-12T01:14:05Z")

</div>

I would like to write a rule to detect if the file name & path are matching for china chopper webshells from below list. for entire csv What is the best way to do please guide me with exact steps. I know we need creat…

---

## [Display the DNS of the visiting IP](https://discuss.elastic.co/t/display-the-dns-of-the-visiting-ip/272174)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 6\
**Last updated:** [May 11, 2021, 10:38am UTC](https://discuss.elastic.co/t/display-the-dns-of-the-visiting-ip/272174 "2021-05-11T10:38:40Z")

</div>

Hi, In SEIM I can see the DNS requests coming out from my machine. Like when I'm visiting google it is logged here in SIEM --\> Network --\> DNS I need the contrary, How can I see the DNS of the IP's visiting my machin…

---

## [Way to place new line space using Webhook request](https://discuss.elastic.co/t/way-to-place-new-line-space-using-webhook-request/272413)

<div class="topic-metadata">

**Author:** [@Suro](https://discuss.elastic.co/u/Suro)\
**Replies:** 1\
**Last updated:** [May 9, 2021, 8:38pm UTC](https://discuss.elastic.co/t/way-to-place-new-line-space-using-webhook-request/272413 "2021-05-09T20:38:43Z")

</div>

We are trying to call ServiceNow Webhook API calls via Elastic Security signal actions. For Eg, we are using the following body below - { "short\_description":"{{context.rule.name}}", "description":"""Rule Descri…

---

## [How to discard specific event from storing or correlation in SIEM to save resources](https://discuss.elastic.co/t/how-to-discard-specific-event-from-storing-or-correlation-in-siem-to-save-resources/271716)

<div class="topic-metadata">

**Author:** [@zoot](https://discuss.elastic.co/u/zoot)\
**Replies:** 1\
**Last updated:** [May 6, 2021, 11:02pm UTC](https://discuss.elastic.co/t/how-to-discard-specific-event-from-storing-or-correlation-in-siem-to-save-resources/271716 "2021-05-06T23:02:20Z")

</div>

Hi, In SIEM systems events can be discard or filter to safe diskspace and avoid overloading SIEM from noisy events. This way SIEM resources can be managed at optimum levels. For example windows event 5156 from all agen…

---

## [Can't access Detections from a different space](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 9\
**Last updated:** [May 6, 2021, 8:55pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118 "2021-05-06T20:55:49Z")

</div>

Hi, \*Running ELK 7.11.2 Standalone I am trying to setup a user to have access to Security in a separate space. I have been following all directions from the official documentation, but the user can't access the "Detect…

---

## [SIEM with Basic License On-Prem?](https://discuss.elastic.co/t/siem-with-basic-license-on-prem/272109)

<div class="topic-metadata">

**Author:** [@R99Stny](https://discuss.elastic.co/u/R99Stny)\
**Replies:** 1\
**Last updated:** [May 5, 2021, 12:56am UTC](https://discuss.elastic.co/t/siem-with-basic-license-on-prem/272109 "2021-05-05T00:56:27Z")

</div>

We have a 3 node cluster on prem 7.6. Couple questions: Based on the docs we should be able to see and use pre-built detections with only a basic license? We do need (required to) have tls/ssl set up within the cluster…

---

## [Failed to fetch rules and timelines: Failed to parse field \[filter\]: x\_content\_parse\_exception](https://discuss.elastic.co/t/failed-to-fetch-rules-and-timelines-failed-to-parse-field-filter-x-content-parse-exception/269624)

<div class="topic-metadata">

**Author:** [@aditi\_salunke](https://discuss.elastic.co/u/aditi_salunke)\
**Replies:** 2\
**Last updated:** [April 29, 2021, 3:42pm UTC](https://discuss.elastic.co/t/failed-to-fetch-rules-and-timelines-failed-to-parse-field-filter-x-content-parse-exception/269624 "2021-04-29T15:42:03Z")

</div>

I am unable to find what went wrong. Can anyone help me out ? PS: 1)Not able to see pre-configured rules and customised one(for superuser role) 2)No alert is getting triggered

---

## [Detection Custom Rule not working](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578)

<div class="topic-metadata">

**Author:** [@anaghadeoreofficial](https://discuss.elastic.co/u/anaghadeoreofficial)\
**Replies:** 7\
**Last updated:** [April 29, 2021, 3:41pm UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578 "2021-04-29T15:41:18Z")

</div>

We are unable to view custom alerts in the detection module. Showing error as below:

---

## [Watcher vs Detection Rule](https://discuss.elastic.co/t/watcher-vs-detection-rule/271564)

<div class="topic-metadata">

**Author:** [@cjumper](https://discuss.elastic.co/u/cjumper)\
**Replies:** 1\
**Last updated:** [April 29, 2021, 4:58am UTC](https://discuss.elastic.co/t/watcher-vs-detection-rule/271564 "2021-04-29T04:58:17Z")

</div>

Try to get a better understanding of the 2. Can someone explain to me the difference between a watcher and a detection rule?

---

## [Machine Learning Functions](https://discuss.elastic.co/t/machine-learning-functions/271404)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 3\
**Last updated:** [April 28, 2021, 10:06pm UTC](https://discuss.elastic.co/t/machine-learning-functions/271404 "2021-04-28T22:06:12Z")

</div>

If i had a Datafeed that spammed multiple docs at once ( for example botnetalert, it triggered 20x ) What is the best function to use to just alert of that one event of all 20 events this is in a short period of course …

---

## [Threat Intel Module for Elastic cloud](https://discuss.elastic.co/t/threat-intel-module-for-elastic-cloud/271198)

<div class="topic-metadata">

**Author:** [@zoot](https://discuss.elastic.co/u/zoot)\
**Replies:** 7\
**Last updated:** [April 28, 2021, 4:15pm UTC](https://discuss.elastic.co/t/threat-intel-module-for-elastic-cloud/271198 "2021-04-28T16:15:00Z")

</div>

Hi, I am using Elastic Cloud for SEIM + Endpoint Security usecase. I want to integrate OTX as threat intel source but from the documentation it seems I need to use some different system instead of adding integration dir…

---

## [Creating a threshold based rule in the detection engine](https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941)

<div class="topic-metadata">

**Author:** [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Replies:** 2\
**Last updated:** [April 28, 2021, 2:51pm UTC](https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941 "2021-04-28T14:51:06Z")

</div>

I'm managing logs of a particular server, I'm defining an activity of a person with some username to be suspicious if there is sudden increase in their activity( i.e., user logs into server 100 times whereas on average h…

---

## [Create a rule to detect number of beats](https://discuss.elastic.co/t/create-a-rule-to-detect-number-of-beats/270366)

<div class="topic-metadata">

**Author:** [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Replies:** 4\
**Last updated:** [April 28, 2021, 8:37am UTC](https://discuss.elastic.co/t/create-a-rule-to-detect-number-of-beats/270366 "2021-04-28T08:37:15Z")

</div>

Hello, I would like to create a new rule to detect if one of my beats stop sending data to my Cluster (one rule for each beat). For example I have installed packetbeat in 5 machines, and then the rule will verify each …

---

## [Ubuntu system log parsing](https://discuss.elastic.co/t/ubuntu-system-log-parsing/271293)

<div class="topic-metadata">

**Author:** [@Guncixx](https://discuss.elastic.co/u/Guncixx)\
**Replies:** 1\
**Last updated:** [April 27, 2021, 1:30am UTC](https://discuss.elastic.co/t/ubuntu-system-log-parsing/271293 "2021-04-27T01:30:35Z")

</div>

Hi, I’m new to Elastic and trying to explore it’s security capabilities. For the testing purpose I set up some VMs and installed elastic agent to collect logs. I then tried to generate some successful and some unsuccess…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=10)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=12)
