# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=12

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 13

---

## [Security not appear data](https://discuss.elastic.co/t/security-not-appear-data/271029)

<div class="topic-metadata">

**Author:** [@syafeera](https://discuss.elastic.co/u/syafeera)\
**Replies:** 2\
**Last updated:** [April 26, 2021, 12:50am UTC](https://discuss.elastic.co/t/security-not-appear-data/271029 "2021-04-26T00:50:03Z")

</div>

HI, may i know, why my data not display in security in kibana. Previously i'm using basic license. then i extend it to trial license. however, i saw my data for auditbeat and filebeat appear in discovery. but i just con…

---

## [Correlation rules not working](https://discuss.elastic.co/t/correlation-rules-not-working/271147)

<div class="topic-metadata">

**Author:** [@Nil\_Battey\_Sannata](https://discuss.elastic.co/u/Nil_Battey_Sannata)\
**Replies:** 0\
**Last updated:** [April 24, 2021, 2:35pm UTC](https://discuss.elastic.co/t/correlation-rules-not-working/271147 "2021-04-24T14:35:46Z")

</div>

I was trying to test some of the prebuilt elastic detection rules with my Beat-Elasticsearch-Kibana setup. All other rules with simple query was working but the rules with event correlation was not working. I tried all p…

---

## [ML Job](https://discuss.elastic.co/t/ml-job/270906)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 2\
**Last updated:** [April 22, 2021, 7:45pm UTC](https://discuss.elastic.co/t/ml-job/270906 "2021-04-22T19:45:46Z")

</div>

Hi! I've created a machine learning job from scratch and, now, when I want to create a detection rules for this job, I cannot see it in that list. I have one node where can be opened 20 jobs, but it is the only one act…

---

## [Alerts from prebuilt detection rules](https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633)

<div class="topic-metadata">

**Author:** [@NightSpark](https://discuss.elastic.co/u/NightSpark)\
**Replies:** 2\
**Last updated:** [April 21, 2021, 2:30am UTC](https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633 "2021-04-21T02:30:19Z")

</div>

Hi, I am running 7.12 and would like to send an alerts to slack whenever a positive match occurs on one of the prebuilt detection rules. i.e Prebuilt rule reference | Elastic Security Solution \[7.12\] | Elastic I can s…

---

## [Detection rule CLI error](https://discuss.elastic.co/t/detection-rule-cli-error/270333)

<div class="topic-metadata">

**Author:** [@Nil\_Battey\_Sannata](https://discuss.elastic.co/u/Nil_Battey_Sannata)\
**Replies:** 1\
**Last updated:** [April 19, 2021, 7:59am UTC](https://discuss.elastic.co/t/detection-rule-cli-error/270333 "2021-04-19T07:59:31Z")

</div>

Hi, I am trying to import Detection RUles with CLI but facing errors as per attached snapshot. I am using self signed cert.

---

## [Email Action for Detection Rule](https://discuss.elastic.co/t/email-action-for-detection-rule/270270)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 2\
**Last updated:** [April 15, 2021, 7:12pm UTC](https://discuss.elastic.co/t/email-action-for-detection-rule/270270 "2021-04-15T19:12:41Z")

</div>

Hi! I wonder if it is possible to change the format of email action using a little bit of html or something close to it. Is there any option? Thank you!

---

## [Valuelists in EQL (correlation) & Threshold Rules](https://discuss.elastic.co/t/valuelists-in-eql-correlation-threshold-rules/268355)

<div class="topic-metadata">

**Author:** [@tushar.bansal](https://discuss.elastic.co/u/tushar.bansal)\
**Replies:** 2\
**Last updated:** [April 15, 2021, 4:31pm UTC](https://discuss.elastic.co/t/valuelists-in-eql-correlation-threshold-rules/268355 "2021-04-15T16:31:25Z")

</div>

Why Can't we add value lists as condition in Correlation Rule Type & Threshold Rule Types even in 7.12? We can only add value lists in indicator match type rules. Why?

---

## [SIEM Detection rule reload](https://discuss.elastic.co/t/siem-detection-rule-reload/270045)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 4\
**Last updated:** [April 14, 2021, 10:07pm UTC](https://discuss.elastic.co/t/siem-detection-rule-reload/270045 "2021-04-14T22:07:21Z")

</div>

Due to a rather nasty upgrade that resulted in a bugs. One of which is every SIEM rule no longer works each one has a different reason so going 1 by 1 isn't really an option. Is it possible to wipe and reload all rules …

---

## [Value Lists as Exception in Threshold and Correlation type rules](https://discuss.elastic.co/t/value-lists-as-exception-in-threshold-and-correlation-type-rules/268353)

<div class="topic-metadata">

**Author:** [@tushar.bansal](https://discuss.elastic.co/u/tushar.bansal)\
**Replies:** 1\
**Last updated:** [April 13, 2021, 1:20am UTC](https://discuss.elastic.co/t/value-lists-as-exception-in-threshold-and-correlation-type-rules/268353 "2021-04-13T01:20:53Z")

</div>

Why Can't we add value list as exception for Threshold rules and correlation rules even in 7.12?

---

## ["Azure Excessive Signin Logs by Azure Identity" unusable azure.signinlogs.identity](https://discuss.elastic.co/t/azure-excessive-signin-logs-by-azure-identity-unusable-azure-signinlogs-identity/269708)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [April 12, 2021, 9:55pm UTC](https://discuss.elastic.co/t/azure-excessive-signin-logs-by-azure-identity-unusable-azure-signinlogs-identity/269708 "2021-04-12T21:55:03Z")

</div>

Hello, Just noticed that in the rule "Azure Excessive Signin Logs by Azure Identity" it seems impossible to display the field azure.signinlogs.identity, which is not very user friendly and a waste of time to lookup afte…

---

## [Unable to use SIEM module](https://discuss.elastic.co/t/unable-to-use-siem-module/268033)

<div class="topic-metadata">

**Author:** [@new2\_elk](https://discuss.elastic.co/u/new2_elk)\
**Replies:** 10\
**Last updated:** [April 8, 2021, 11:33am UTC](https://discuss.elastic.co/t/unable-to-use-siem-module/268033 "2021-04-08T11:33:26Z")

</div>

Hi All, I have setup a lab environment with below configuration: Lab firewall sending log -\> (Filebeat -\> Logstash -\> Elasticsearch) which Fliebeat, logstash, Elasticsearch is on Alibaba Cloud. When I try to use the S…

---

## [How to create a rule with aggregation](https://discuss.elastic.co/t/how-to-create-a-rule-with-aggregation/269023)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 4\
**Last updated:** [April 6, 2021, 7:57am UTC](https://discuss.elastic.co/t/how-to-create-a-rule-with-aggregation/269023 "2021-04-06T07:57:22Z")

</div>

Hello, I would like to create a rule where I can detect brute force attack For example: in winlogbeat-\* and auditbeat-\* where event.action == logon-failed, aggregation by user.name , and if it's more than 10, it creat…

---

## [SIEM (Kibana) not working with some errors](https://discuss.elastic.co/t/siem-kibana-not-working-with-some-errors/267657)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 1\
**Last updated:** [April 5, 2021, 10:20am UTC](https://discuss.elastic.co/t/siem-kibana-not-working-with-some-errors/267657 "2021-04-05T10:20:43Z")

</div>

I have the full ELK cluster experience with Filebeat sending logst to Logstash and there I do all my processing. I very recently learned that in order to have nested fields you should write "\[host\]\[name\]" rather than "ho…

---

## [SIgma rules for Elastic SIEM](https://discuss.elastic.co/t/sigma-rules-for-elastic-siem/268453)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 4\
**Last updated:** [April 3, 2021, 4:42am UTC](https://discuss.elastic.co/t/sigma-rules-for-elastic-siem/268453 "2021-04-03T04:42:49Z")

</div>

Hello! I need to use Sigma rules repo for my SIEM. How I can translate sigma to elastic? And how I can perform auto update sigma rules?

---

## [Alert and connect mail format error](https://discuss.elastic.co/t/alert-and-connect-mail-format-error/268998)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 9\
**Last updated:** [April 2, 2021, 1:26pm UTC](https://discuss.elastic.co/t/alert-and-connect-mail-format-error/268998 "2021-04-02T13:26:14Z")

</div>

Hi all i have some question I was trying the version 7.12 for the first time, what interest me the most was that kibana finally have mail format for the siem rule, well i try cortext.alert just like how they show on gi…

---

## [Detection rules CLI](https://discuss.elastic.co/t/detection-rules-cli/268867)

<div class="topic-metadata">

**Author:** [@aditi\_salunke](https://discuss.elastic.co/u/aditi_salunke)\
**Replies:** 2\
**Last updated:** [April 1, 2021, 5:05pm UTC](https://discuss.elastic.co/t/detection-rules-cli/268867 "2021-04-01T17:05:20Z")

</div>

Traceback (most recent call last): File "/usr/lib64/python3.8/runpy.py", line 194, in \_run\_module\_as\_main return \_run\_code(code, main\_globals, None, File "/usr/lib64/python3.8/runpy.py", line 87, in \_run\_code …

---

## [Jira Action sending broken links on detection jobs](https://discuss.elastic.co/t/jira-action-sending-broken-links-on-detection-jobs/268809)

<div class="topic-metadata">

**Author:** [@Balor](https://discuss.elastic.co/u/Balor)\
**Replies:** 1\
**Last updated:** [April 1, 2021, 5:01pm UTC](https://discuss.elastic.co/t/jira-action-sending-broken-links-on-detection-jobs/268809 "2021-04-01T17:01:21Z")

</div>

Hello Elastic discuss, Am on: ECE 2.9.0 Elastic 7.12. I have been using the Detection API to add actions to certain Detection jobs. I am using a Jira connector. Am seeing this sort of behaviour in the action messag…

---

## [Specific steps to build monitoring and siem with elk](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605)

<div class="topic-metadata">

**Author:** [@Depressed](https://discuss.elastic.co/u/Depressed)\
**Replies:** 3\
**Last updated:** [March 29, 2021, 9:09pm UTC](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605 "2021-03-29T21:09:09Z")

</div>

Hi I'm kinda new to whole siem and elk things and before i managed to setup monitoring with splunk cracked enterprise edition and there all was simple as forwarding data from netflow ,syslog ,snmp and defining new fi…

---

## [Detection threshold rule problem](https://discuss.elastic.co/t/detection-threshold-rule-problem/268079)

<div class="topic-metadata">

**Author:** [@Jorge7](https://discuss.elastic.co/u/Jorge7)\
**Replies:** 5\
**Last updated:** [March 25, 2021, 10:23am UTC](https://discuss.elastic.co/t/detection-threshold-rule-problem/268079 "2021-03-25T10:23:27Z")

</div>

Hi everyone, I'm try to create a personalize rule with the threshold parameter detection. I am using a handmade index with personal fields. This is the mapping: { "login-000001" : { "mappings" : { "properti…

---

## [Fleet Agent Goes from Online to Offline](https://discuss.elastic.co/t/fleet-agent-goes-from-online-to-offline/266745)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 1\
**Last updated:** [March 24, 2021, 6:04pm UTC](https://discuss.elastic.co/t/fleet-agent-goes-from-online-to-offline/266745 "2021-03-24T18:04:11Z")

</div>

I enrolled my agent, but after a few minutes it goes offline .I found errors in my endpoint agent logs The error is "Error \[SSL certificate problem: self signed certificate in certificate chain\]". I was able to bypass th…

---

## [Unable to forward watcher alert to index with all details](https://discuss.elastic.co/t/unable-to-forward-watcher-alert-to-index-with-all-details/268048)

<div class="topic-metadata">

**Author:** [@aditi\_salunke](https://discuss.elastic.co/u/aditi_salunke)\
**Replies:** 2\
**Last updated:** [March 24, 2021, 5:54am UTC](https://discuss.elastic.co/t/unable-to-forward-watcher-alert-to-index-with-all-details/268048 "2021-03-24T05:54:51Z")

</div>

{ "trigger": { "schedule": { "interval": "15m" } }, "input": { "search": { "request": { "search\_type": "query\_then\_fetch", "indices": \[ "##selective index##" …

---

## [Issue with Signals in ELK7.8](https://discuss.elastic.co/t/issue-with-signals-in-elk7-8/266699)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 3\
**Last updated:** [March 23, 2021, 11:02pm UTC](https://discuss.elastic.co/t/issue-with-signals-in-elk7-8/266699 "2021-03-23T23:02:33Z")

</div>

Hi, I have 200 rule signals running. There are 80 Elastic default rules and 120 custom rules. Last response of most of the rules are showing succeeded but last run is 6 days ago and more. There is no error message. Pl…

---

## [How to define time range in custom query rule in elasticsiem?](https://discuss.elastic.co/t/how-to-define-time-range-in-custom-query-rule-in-elasticsiem/267521)

<div class="topic-metadata">

**Author:** [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Replies:** 5\
**Last updated:** [March 23, 2021, 8:41pm UTC](https://discuss.elastic.co/t/how-to-define-time-range-in-custom-query-rule-in-elasticsiem/267521 "2021-03-23T20:41:37Z")

</div>

Hi, I'm trying to create rule which should fire on admin activity when time of event is from 22:00 till 5:00. I tried this query: user.group.name :\*admin\* and ((@timestamp \>= "00:00:00" and @timestamp \<= "05:00:00" ) …

---

## [Edit Telnet port Activity rule](https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 2\
**Last updated:** [March 22, 2021, 10:04am UTC](https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061 "2021-03-22T10:04:47Z")

</div>

Hi, The Telnet Port Activity detection rule triggers whenever there is port scan / activity is tried Even if the port is closed How can I edit the below rule to trigger ONLY if port is open? event.category:(network or…

---

## [Reporting email action failure from watcher - ELK7.8](https://discuss.elastic.co/t/reporting-email-action-failure-from-watcher-elk7-8/267322)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 2\
**Last updated:** [March 18, 2021, 6:16pm UTC](https://discuss.elastic.co/t/reporting-email-action-failure-from-watcher-elk7-8/267322 "2021-03-18T18:16:36Z")

</div>

Hi Team, Please help me to resolve the email action failure error mentioned below from watcher. I am using ELK version 7.8. "id": "email\_action", "type": "email", "status": "failure", "error": { "root\_cause": \[ { …

---

## [Fortinet.tmp.\*](https://discuss.elastic.co/t/fortinet-tmp/267213)

<div class="topic-metadata">

**Author:** [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Replies:** 8\
**Last updated:** [March 17, 2021, 4:28am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213 "2021-03-17T04:28:17Z")

</div>

Hi, I'm trying out fortinet filebeat plugin. Running ELK with 7.10.1 and filebeat 7.10.1 However, I'm getting a strange input values into the documents (in the filebeat-\* index) This is my config - module: fortin…

---

## [Match rule not working](https://discuss.elastic.co/t/match-rule-not-working/266666)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 6\
**Last updated:** [March 11, 2021, 8:51am UTC](https://discuss.elastic.co/t/match-rule-not-working/266666 "2021-03-11T08:51:25Z")

</div>

Hello, I am trying to add a threat intelligence in my SIEM, I downloaded the database of malware hashes, and I am using auditbeat file integrity to detect malware, and then I created a rmatch rule like that: and the…

---

## [Index/API end point to edit detection rules?](https://discuss.elastic.co/t/index-api-end-point-to-edit-detection-rules/266401)

<div class="topic-metadata">

**Author:** [@aidanoc15](https://discuss.elastic.co/u/aidanoc15)\
**Replies:** 1\
**Last updated:** [March 8, 2021, 12:12pm UTC](https://discuss.elastic.co/t/index-api-end-point-to-edit-detection-rules/266401 "2021-03-08T12:12:33Z")

</div>

Hi, we are currently in the process of migrating off of our old SIEM and into elastic siem. We have created a bunch of detection rules already in Elastic but we still need to move over all the exceptions for those rules …

---

## [Detection Failiure in ELK7.8 SIEM](https://discuss.elastic.co/t/detection-failiure-in-elk7-8-siem/266217)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 1\
**Last updated:** [March 5, 2021, 10:18pm UTC](https://discuss.elastic.co/t/detection-failiure-in-elk7-8-siem/266217 "2021-03-05T22:18:07Z")

</div>

Hello, It is noticed that detection rule is getting failed by showing the bellow error message. "Consider increasing your look back time or adding more Kibana instances." I have tried increasing the look back time fro…

---

## [Indicator match rule not matched and Mapped with filebeat-\* (MISP Module)](https://discuss.elastic.co/t/indicator-match-rule-not-matched-and-mapped-with-filebeat-misp-module/266315)

<div class="topic-metadata">

**Author:** [@raviraja](https://discuss.elastic.co/u/raviraja)\
**Replies:** 1\
**Last updated:** [March 5, 2021, 10:01pm UTC](https://discuss.elastic.co/t/indicator-match-rule-not-matched-and-mapped-with-filebeat-misp-module/266315 "2021-03-05T22:01:05Z")

</div>

Hi guys, We are using ELK 7.11.1 version. We have ingested threat intelligence feeds from MISP server and stored in Elasticsearch through Filebeat.(Using Module MISP) and we want to map and match with Zscalerlog. Base…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=11)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=13)
