# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=13

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 14

---

## [Filebeat module's fields in SIEM columns](https://discuss.elastic.co/t/filebeat-modules-fields-in-siem-columns/266090)

<div class="topic-metadata">

**Author:** [@radovan](https://discuss.elastic.co/u/radovan)\
**Replies:** 1\
**Last updated:** [March 5, 2021, 7:42pm UTC](https://discuss.elastic.co/t/filebeat-modules-fields-in-siem-columns/266090 "2021-03-05T19:42:34Z")

</div>

Hi, after upgrading our cluster from 7.10.2 to 7.11.1 we can no more see values of filebeat module's fields in columns, for example suricata's fields (screenshot below), although they are included in the signal's fi…

---

## [Threshold Detection Ignoring Group By Field](https://discuss.elastic.co/t/threshold-detection-ignoring-group-by-field/264873)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 6\
**Last updated:** [March 4, 2021, 3:02pm UTC](https://discuss.elastic.co/t/threshold-detection-ignoring-group-by-field/264873 "2021-03-04T15:02:10Z")

</div>

Hi I have upgraded to 7.11.0 and now 7.11.1 and I think there is an issue with Threshold detections. I have a simple detection based on my FW logs. It looks for flow\_denied or flow\_dropped messages and raises a detect…

---

## [Detection Rules Triggered although ports are closed!](https://discuss.elastic.co/t/detection-rules-triggered-although-ports-are-closed/266207)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 0\
**Last updated:** [March 4, 2021, 10:05am UTC](https://discuss.elastic.co/t/detection-rules-triggered-although-ports-are-closed/266207 "2021-03-04T10:05:44Z")

</div>

Hi, In SEIM, I can see some detection rules are triggered like although the related ports are already closed: signal.rule.name: "Telnet Port Activity" (which works on port 23) and signal.rule.name: "SMTP on Port 26/…

---

## [Indicator Match Detection Rule Not Matched and Mapped to Intel Feeds](https://discuss.elastic.co/t/indicator-match-detection-rule-not-matched-and-mapped-to-intel-feeds/262446)

<div class="topic-metadata">

**Author:** [@ikbal](https://discuss.elastic.co/u/ikbal)\
**Replies:** 16\
**Last updated:** [March 4, 2021, 3:06am UTC](https://discuss.elastic.co/t/indicator-match-detection-rule-not-matched-and-mapped-to-intel-feeds/262446 "2021-03-04T03:06:22Z")

</div>

Hi guys, We are using ES 7.10.1 altogether with Logstash and Kibana. We have ingested TI feeds from MISP and index named as filebeat and we wanted to map and match it to Zscaler logs. We have tested tens of times just…

---

## [Detection not finding anything but same query finds them](https://discuss.elastic.co/t/detection-not-finding-anything-but-same-query-finds-them/265535)

<div class="topic-metadata">

**Author:** [@plaroche0](https://discuss.elastic.co/u/plaroche0)\
**Replies:** 5\
**Last updated:** [February 27, 2021, 1:57pm UTC](https://discuss.elastic.co/t/detection-not-finding-anything-but-same-query-finds-them/265535 "2021-02-27T13:57:39Z")

</div>

I made a detection from a saved query that shows what I want to detect but the detection is not detecting anything. Detection does not show any failures. Any suggestions?

---

## [EQL signal query return with error](https://discuss.elastic.co/t/eql-signal-query-return-with-error/265465)

<div class="topic-metadata">

**Author:** [@qiratnahraf](https://discuss.elastic.co/u/qiratnahraf)\
**Replies:** 1\
**Last updated:** [February 25, 2021, 3:33pm UTC](https://discuss.elastic.co/t/eql-signal-query-return-with-error/265465 "2021-02-25T15:33:18Z")

</div>

Hi, We are on 7.10 and trying to use EQL signal but hit with error, although when we execute the same EQL query from console it successfully return results. please note in detection module we hit with error whenever we t…

---

## [Default email recipient address in email action in ELK7.8 Signals or 7.11 detections](https://discuss.elastic.co/t/default-email-recipient-address-in-email-action-in-elk7-8-signals-or-7-11-detections/265304)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 1\
**Last updated:** [February 24, 2021, 8:23pm UTC](https://discuss.elastic.co/t/default-email-recipient-address-in-email-action-in-elk7-8-signals-or-7-11-detections/265304 "2021-02-24T20:23:16Z")

</div>

Hello, Please let me know if there any option to configure recipient email address in a common file instead of configuring in each detection rules. This is really difficult task to manually configure email address in e…

---

## [Elastic security fields data not showing in Timeline](https://discuss.elastic.co/t/elastic-security-fields-data-not-showing-in-timeline/264235)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 2\
**Last updated:** [February 24, 2021, 1:40pm UTC](https://discuss.elastic.co/t/elastic-security-fields-data-not-showing-in-timeline/264235 "2021-02-24T13:40:55Z")

</div>

Hi Team, We are not able to see proper data in timeline of elastic security module. issue 1: Summary not showing the correct data of detection rule Issue 2: Some field values are not showing in the timeline window…

---

## [Kibana Cases Analytics](https://discuss.elastic.co/t/kibana-cases-analytics/265116)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 5\
**Last updated:** [February 23, 2021, 6:55am UTC](https://discuss.elastic.co/t/kibana-cases-analytics/265116 "2021-02-23T06:55:39Z")

</div>

Hello, I need to do some basic analytics on the Kibana cases we created until now. Where are these cases indexed? For example I added some tags and I want to visualise the amount of cases out of all cases that have cert…

---

## [Alert Variables in email action - EQL](https://discuss.elastic.co/t/alert-variables-in-email-action-eql/264695)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 3\
**Last updated:** [February 22, 2021, 5:32pm UTC](https://discuss.elastic.co/t/alert-variables-in-email-action-eql/264695 "2021-02-22T17:32:42Z")

</div>

Hello, Can someone please help to add additional field to the alert variable? I have mentioned the Detection EQL rule logic below. sequence with maxspan=5m \[authentication where event.type == "authentication\_failure"\]…

---

## [D365 cloud based solution](https://discuss.elastic.co/t/d365-cloud-based-solution/264664)

<div class="topic-metadata">

**Author:** [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Replies:** 1\
**Last updated:** [February 19, 2021, 12:02pm UTC](https://discuss.elastic.co/t/d365-cloud-based-solution/264664 "2021-02-19T12:02:43Z")

</div>

Hi There, Is it possible to extract the Dynamics 365 logs via filebeat? like Office 365 Hello, we're looking to better secure our Dynamics 365 instance, and we're wondering what were good options for logging admin e…

---

## [SIEM Detection alerts - Additional field adding in notification placeholders](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 3\
**Last updated:** [February 18, 2021, 10:48pm UTC](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247 "2021-02-18T22:48:15Z")

</div>

Hi, How can i add additional fields in alert email action body in detection rules. I am using ELK 7.10. For eg: Need to include user.name and source.ip field in the rule alert in the body of alert email action. Rule L…

---

## [ELK 7.10 - Indicator index patterns: Value lists](https://discuss.elastic.co/t/elk-7-10-indicator-index-patterns-value-lists/264287)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 2\
**Last updated:** [February 15, 2021, 4:22pm UTC](https://discuss.elastic.co/t/elk-7-10-indicator-index-patterns-value-lists/264287 "2021-02-15T16:22:24Z")

</div>

Hello, I am trying to create a indicator match rule in ELK 7.10 where i have to give the indicator index pattern. Is there any default indicator index in ELK 7.10 or do i need to create a new indicator index with IOC lo…

---

## [How to give access to Security Cases of one Kibana Space to the users in another Kibana Space?](https://discuss.elastic.co/t/how-to-give-access-to-security-cases-of-one-kibana-space-to-the-users-in-another-kibana-space/264032)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [February 12, 2021, 2:38pm UTC](https://discuss.elastic.co/t/how-to-give-access-to-security-cases-of-one-kibana-space-to-the-users-in-another-kibana-space/264032 "2021-02-12T14:38:07Z")

</div>

Hello, Is it possible to give access to Security Cases of one Kibana Space to the users in another Kibana Space? For example we have an engineer team Kibana where the detections are running, but our security officers a…

---

## [Managing SIEM rules is harder then it should](https://discuss.elastic.co/t/managing-siem-rules-is-harder-then-it-should/263864)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [February 11, 2021, 2:40pm UTC](https://discuss.elastic.co/t/managing-siem-rules-is-harder-then-it-should/263864 "2021-02-11T14:40:44Z")

</div>

Hello, I'd like to make some suggestions about the Elastic SIEM rule management. Monday we had a major hardware failure of a network card of on of our hot data nodes. The node in particular was not completely offline a…

---

## [Elastic SIEM - Detection Rules - Combination of Time-based, Threshold, Aggregation and Sequence Events](https://discuss.elastic.co/t/elastic-siem-detection-rules-combination-of-time-based-threshold-aggregation-and-sequence-events/263175)

<div class="topic-metadata">

**Author:** [@tushar.bansal](https://discuss.elastic.co/u/tushar.bansal)\
**Replies:** 6\
**Last updated:** [February 5, 2021, 6:11pm UTC](https://discuss.elastic.co/t/elastic-siem-detection-rules-combination-of-time-based-threshold-aggregation-and-sequence-events/263175 "2021-02-05T18:11:20Z")

</div>

How to create rule to detect: "Successful Brute Force Attack" (When more than 10 Windows logout events (ID 4625) occur AND followed by a Windows login event (ID 4624) on a same host) in 5 minutes timespan Thresholds: N…

---

## [Customize SIEM Detection columns based on alert](https://discuss.elastic.co/t/customize-siem-detection-columns-based-on-alert/263228)

<div class="topic-metadata">

**Author:** [@madduck](https://discuss.elastic.co/u/madduck)\
**Replies:** 1\
**Last updated:** [February 5, 2021, 2:57pm UTC](https://discuss.elastic.co/t/customize-siem-detection-columns-based-on-alert/263228 "2021-02-05T14:57:41Z")

</div>

Hello, it seems like the Columns in the SIEM Application are more or less static and if I want a new value to de displayed I have to add it to the entire mask which might lead to unpopulated fields in certain alerts. T…

---

## [Detection Rules: Time Frame Based Exceptions](https://discuss.elastic.co/t/detection-rules-time-frame-based-exceptions/263036)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 4\
**Last updated:** [February 3, 2021, 2:46pm UTC](https://discuss.elastic.co/t/detection-rules-time-frame-based-exceptions/263036 "2021-02-03T14:46:25Z")

</div>

Hi All, I was wondering if it's possible to added time based exceptions to detection rules? An example would be with some of the current detection rules, they get triggered during system patching. Ideally it would be ni…

---

## [ML job - detect new port](https://discuss.elastic.co/t/ml-job-detect-new-port/263107)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 2\
**Last updated:** [February 3, 2021, 11:58am UTC](https://discuss.elastic.co/t/ml-job-detect-new-port/263107 "2021-02-03T11:58:39Z")

</div>

Hi, I am sending vulnerability scan results into the SIEM and trying to detect new ports scanned for an assest. Ive tried using Rare, by field: port and partition: asset but the results are coming back empty. It could…

---

## [SIEM Rule Failures](https://discuss.elastic.co/t/siem-rule-failures/260409)

<div class="topic-metadata">

**Author:** [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Replies:** 5\
**Last updated:** [February 1, 2021, 9:39pm UTC](https://discuss.elastic.co/t/siem-rule-failures/260409 "2021-02-01T21:39:14Z")

</div>

Hello Everyone, We are on Elastic 7.9 and are mainly using it as a SIEM, suddenly all of the SIEM rules start to fail and not just some but all of them.

---

## [Bulk indexing of signals failed in Kibana 7.10.2](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-in-kibana-7-10-2/262373)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 7\
**Last updated:** [January 29, 2021, 9:29pm UTC](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-in-kibana-7-10-2/262373 "2021-01-29T21:29:30Z")

</div>

Hello, Just noticed our custom SIEM rules seem to throw errors, such as: Bulk Indexing of signals failed: reason: "No mapping found for \[@timestamp\] in order to sort on" type: "query\_shard\_exception" name: "Elastic Aud…

---

## [Action export selected signals to csv](https://discuss.elastic.co/t/action-export-selected-signals-to-csv/262497)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 7\
**Last updated:** [January 29, 2021, 4:04pm UTC](https://discuss.elastic.co/t/action-export-selected-signals-to-csv/262497 "2021-01-29T16:04:29Z")

</div>

hello, Just a thought for a SIEM feature. We have colleagues with limited or no acces to Elastic / Kibana. But sometimes they do need to get a list of some signals. Imho it would be super handy to be able to quickly exp…

---

## [Recommended practise for detection tuning; filters or exceptions](https://discuss.elastic.co/t/recommended-practise-for-detection-tuning-filters-or-exceptions/262218)

<div class="topic-metadata">

**Author:** [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Replies:** 7\
**Last updated:** [January 28, 2021, 12:36pm UTC](https://discuss.elastic.co/t/recommended-practise-for-detection-tuning-filters-or-exceptions/262218 "2021-01-28T12:36:27Z")

</div>

Hi, I have given a look through the documentation but did not come across anything conclusive. What is the recommended way of tuning detection rules, as you can get the same results from filters and exceptions. Can yo…

---

## [Event.action field for cloudTrail logs not being assigned event name when pulling cloud-trail logs using aws module](https://discuss.elastic.co/t/event-action-field-for-cloudtrail-logs-not-being-assigned-event-name-when-pulling-cloud-trail-logs-using-aws-module/261621)

<div class="topic-metadata">

**Author:** [@kbirhan](https://discuss.elastic.co/u/kbirhan)\
**Replies:** 0\
**Last updated:** [January 20, 2021, 8:16am UTC](https://discuss.elastic.co/t/event-action-field-for-cloudtrail-logs-not-being-assigned-event-name-when-pulling-cloud-trail-logs-using-aws-module/261621 "2021-01-20T08:16:35Z")

</div>

Hi I was looking into my cloudtrail logs i am pulling from s3 bucket, and it seems aws module of filebeat seems to give a generic value ("mangement") for the event.action field. As shown in the image,all event.action fi…

---

## [\[SIEM\] Authentications table doesn't show 'Last Success/Failed Source' column if only 'source.ip' is present](https://discuss.elastic.co/t/siem-authentications-table-doesnt-show-last-success-failed-source-column-if-only-source-ip-is-present/261257)

<div class="topic-metadata">

**Author:** [@eextreemee](https://discuss.elastic.co/u/eextreemee)\
**Replies:** 6\
**Last updated:** [January 19, 2021, 5:25pm UTC](https://discuss.elastic.co/t/siem-authentications-table-doesnt-show-last-success-failed-source-column-if-only-source-ip-is-present/261257 "2021-01-19T17:25:17Z")

</div>

I found solution here but i don't know how to implement it. please help...

---

## [\[ Creating new rule \]: ERROR Authentication using apikey failed - api key has been invalidated](https://discuss.elastic.co/t/creating-new-rule-error-authentication-using-apikey-failed-api-key-has-been-invalidated/261407)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 4\
**Last updated:** [January 19, 2021, 4:53pm UTC](https://discuss.elastic.co/t/creating-new-rule-error-authentication-using-apikey-failed-api-key-has-been-invalidated/261407 "2021-01-19T16:53:45Z")

</div>

Hello, I am using elasticsearch, kibana and beats version 7.10.1 with a Trial license, I am trying to create a new Match rule and in my elasticsearch node I am getting this error: \[2021-01-18T11:33:18,032\]\[WARN \]\[o.e…

---

## [\[ URLHaus threat intelligence \]: create a new rule](https://discuss.elastic.co/t/urlhaus-threat-intelligence-create-a-new-rule/260857)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 17\
**Last updated:** [January 19, 2021, 2:49pm UTC](https://discuss.elastic.co/t/urlhaus-threat-intelligence-create-a-new-rule/260857 "2021-01-19T14:49:23Z")

</div>

Hello, I am using logsatsh to enrich my SIEM with malicious Urls that I downloaded from URLHaus, and I wanna create a rule that send an alert everytime a user connect to one of the malicious urls. The problem is that …

---

## [Why \`elastic-es-default-0\` (which is the pod name for my Elasticsearch) becomes a "host"?](https://discuss.elastic.co/t/why-elastic-es-default-0-which-is-the-pod-name-for-my-elasticsearch-becomes-a-host/261490)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 1\
**Last updated:** [January 19, 2021, 2:12pm UTC](https://discuss.elastic.co/t/why-elastic-es-default-0-which-is-the-pod-name-for-my-elasticsearch-becomes-a-host/261490 "2021-01-19T14:12:08Z")

</div>

It behaves like a host... For example, see the screenshot. The test-one-01106 is a real kubernetes worker machine, but the elastic-es-default-0 is not... Thanks!

---

## [Signal.rule.name empty?](https://discuss.elastic.co/t/signal-rule-name-empty/260823)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [January 18, 2021, 7:08pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823 "2021-01-18T19:08:22Z")

</div>

Hello, Just noticed signal.rule.name is empty for some rules? Elastic 7.9.2 The above screenshot is from the rule "VNC to the Internet" which I copied from the official " VNC (Virtual Network Computing) to the Intern…

---

## [\[ Threshold Rule \]: Unexpected result](https://discuss.elastic.co/t/threshold-rule-unexpected-result/260956)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 5\
**Last updated:** [January 14, 2021, 3:53pm UTC](https://discuss.elastic.co/t/threshold-rule-unexpected-result/260956 "2021-01-14T15:53:47Z")

</div>

Hello, I would like to create a Threshold rule to detect files downloaded more than 1 Go. So in my firewall logs I have the field rcvd where I can find this value, and I to test that, I tested to download a file with 1…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=12)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=14)
