# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=14

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 15

---

## [Questions re elksiem](https://discuss.elastic.co/t/questions-re-elksiem/260561)

<div class="topic-metadata">

**Author:** [@rconroy](https://discuss.elastic.co/u/rconroy)\
**Replies:** 33\
**Last updated:** [January 12, 2021, 7:19pm UTC](https://discuss.elastic.co/t/questions-re-elksiem/260561 "2021-01-12T19:19:14Z")

</div>

OK, so first off, the auditbeats install, one reference had me use the downloaded files ./auditbeat setup method, whereas the other had me install using yum. The yum method didnt appear to install any dashboards and the…

---

## [Detection Rules Column Data Missing](https://discuss.elastic.co/t/detection-rules-column-data-missing/260434)

<div class="topic-metadata">

**Author:** [@Psyhil](https://discuss.elastic.co/u/Psyhil)\
**Replies:** 2\
**Last updated:** [January 12, 2021, 9:47am UTC](https://discuss.elastic.co/t/detection-rules-column-data-missing/260434 "2021-01-12T09:47:31Z")

</div>

Good Day! I have added some custom rules in elastic and running into a problem where fields like host.name, Source IP address and destination IP address are missing in detections UI. I tried to fiddle with the columns …

---

## [Multiple Different Clients](https://discuss.elastic.co/t/multiple-different-clients/258935)

<div class="topic-metadata">

**Author:** [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Replies:** 4\
**Last updated:** [January 4, 2021, 7:25pm UTC](https://discuss.elastic.co/t/multiple-different-clients/258935 "2021-01-04T19:25:00Z")

</div>

Is it possible to use a single instance of Elastic SIEM to monitor two different companies networks and separate them so their information will be separated?

---

## [SIEM detection rule emails body customization](https://discuss.elastic.co/t/siem-detection-rule-emails-body-customization/258416)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 4\
**Last updated:** [December 28, 2020, 9:19pm UTC](https://discuss.elastic.co/t/siem-detection-rule-emails-body-customization/258416 "2020-12-28T21:19:47Z")

</div>

Hi Team, Can you please let me know how i can add additional details to detection rules message body For example , for root login attempt failure , i need the email message body with host.hostname, @timestamp, event.o…

---

## [Detection Alerts - Want To Only See that Alert](https://discuss.elastic.co/t/detection-alerts-want-to-only-see-that-alert/259135)

<div class="topic-metadata">

**Author:** [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Replies:** 7\
**Last updated:** [December 24, 2020, 9:17am UTC](https://discuss.elastic.co/t/detection-alerts-want-to-only-see-that-alert/259135 "2020-12-24T09:17:42Z")

</div>

When clicking on a detection alert it shows the list with a list of other detections during a timeframe is there a way we can make it so it only shows that specific alert and not a list of others. Like make that timefr…

---

## [How to only send an alert when severity is high](https://discuss.elastic.co/t/how-to-only-send-an-alert-when-severity-is-high/259263)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 5\
**Last updated:** [December 22, 2020, 6:40pm UTC](https://discuss.elastic.co/t/how-to-only-send-an-alert-when-severity-is-high/259263 "2020-12-22T18:40:59Z")

</div>

Hello, So I created this rule that triggers on Azure risky signins: Ans as you can see I made an override for the azure.signinlogs.properties.risk\_level\_during\_signin field. But now the alert I configured triggers o…

---

## [Opsgenie SIEM Case connector](https://discuss.elastic.co/t/opsgenie-siem-case-connector/257889)

<div class="topic-metadata">

**Author:** [@Felipe\_Fuller](https://discuss.elastic.co/u/Felipe_Fuller)\
**Replies:** 1\
**Last updated:** [December 22, 2020, 8:11am UTC](https://discuss.elastic.co/t/opsgenie-siem-case-connector/257889 "2020-12-22T08:11:04Z")

</div>

Hi! I'm trying to create a connector to push cases to Jira's Opsgenie from Elastic SIEM. Is it possible? The idea is to do the same that Jiras connector does, but adapted to Opsgenie. Thank you in advance!

---

## [GeoIP processing of detections](https://discuss.elastic.co/t/geoip-processing-of-detections/259319)

<div class="topic-metadata">

**Author:** [@p\_ansell](https://discuss.elastic.co/u/p_ansell)\
**Replies:** 0\
**Last updated:** [December 22, 2020, 1:34am UTC](https://discuss.elastic.co/t/geoip-processing-of-detections/259319 "2020-12-22T01:34:45Z")

</div>

Compared to non-Threshold results that inherit the previously processed fields, Threshold Detection events only include the single field that is being aggregated. I would like to perform GeoIP processing of Threshold Det…

---

## [Elastic SIEM Fields Populate to JIRA Custom Fields](https://discuss.elastic.co/t/elastic-siem-fields-populate-to-jira-custom-fields/259291)

<div class="topic-metadata">

**Author:** [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Replies:** 1\
**Last updated:** [December 21, 2020, 5:51pm UTC](https://discuss.elastic.co/t/elastic-siem-fields-populate-to-jira-custom-fields/259291 "2020-12-21T17:51:47Z")

</div>

Is it possible to populate fields to customer fields in JIRA for a ticket. Like my current set up that I have for AlienVault?

---

## [Custom Rules not working](https://discuss.elastic.co/t/custom-rules-not-working/258421)

<div class="topic-metadata">

**Author:** [@Yuriy\_Tsarenko](https://discuss.elastic.co/u/Yuriy_Tsarenko)\
**Replies:** 7\
**Last updated:** [December 16, 2020, 3:27pm UTC](https://discuss.elastic.co/t/custom-rules-not-working/258421 "2020-12-16T15:27:01Z")

</div>

Hello team! If possible, you could help us with setting up custom rules for SIEM. We had the following problem: The main idea is to create a rule according to which we would receive notifications when someone from the…

---

## [Custom event category in correlation rule](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809)

<div class="topic-metadata">

**Author:** [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Replies:** 4\
**Last updated:** [December 17, 2020, 7:48am UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809 "2020-12-17T07:48:54Z")

</div>

Can anyone please explain what does it means I have Symantec antimalware logs on index pattern logstash-sepm\*. In json document I don't have event.category field but I want to create a correlation rule what if the sa…

---

## [Detection Alerts - Creating JIRA Ticket (Automatically)](https://discuss.elastic.co/t/detection-alerts-creating-jira-ticket-automatically/258930)

<div class="topic-metadata">

**Author:** [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Replies:** 3\
**Last updated:** [December 17, 2020, 6:33am UTC](https://discuss.elastic.co/t/detection-alerts-creating-jira-ticket-automatically/258930 "2020-12-17T06:33:20Z")

</div>

I need to be able to find a way of using the Elastic SIEM API to create tickets in JIRA everytime a Detection Alert comes in. We are trying to basically skip the "CASE" portion of the SIEM too, because it doesn't work f…

---

## [Unusual Parent-Child Relationship Query and process parent hyphen value](https://discuss.elastic.co/t/unusual-parent-child-relationship-query-and-process-parent-hyphen-value/258570)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [December 14, 2020, 7:18pm UTC](https://discuss.elastic.co/t/unusual-parent-child-relationship-query-and-process-parent-hyphen-value/258570 "2020-12-14T19:18:12Z")

</div>

Hello, I'm noticing a large amount of detections on the "Unusual Parent-Child Relationship" detection rule whichs seems to be related to the fact that some processes don't have a parent process. Data source are sysmon f…

---

## [Detection rules](https://discuss.elastic.co/t/detection-rules/257785)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 3\
**Last updated:** [December 14, 2020, 4:08pm UTC](https://discuss.elastic.co/t/detection-rules/257785 "2020-12-14T16:08:00Z")

</div>

How can I check when I make a detection rule if another rule has been activated? That is, if I want to make a rule that verifies an incident I would like to check if another rule that is strictly related to IDS has alrea…

---

## [Rule failure for Windows path exclusions?](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 4\
**Last updated:** [December 9, 2020, 3:26pm UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034 "2020-12-09T15:26:20Z")

</div>

Hello, Elastic 7.9.2 Results in: The working directory values were autocompleted, so this seems weird that this throws an error. When I try to escape the '\\' autocomplete does not work. Grtz Willem

---

## [Auto response (Auto remediation) SIEM](https://discuss.elastic.co/t/auto-response-auto-remediation-siem/257665)

<div class="topic-metadata">

**Author:** [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 2:30pm UTC](https://discuss.elastic.co/t/auto-response-auto-remediation-siem/257665 "2020-12-04T14:30:54Z")

</div>

Hello everybody, I never used a webhook before, so I wanna know if it's possible for example to add automatic rules to my firewall when I detect an attack (brute force, port scanner ...). I have searched webinar for th…

---

## [Security Solution Plugins & @timestamp](https://discuss.elastic.co/t/security-solution-plugins-timestamp/257217)

<div class="topic-metadata">

**Author:** [@teej](https://discuss.elastic.co/u/teej)\
**Replies:** 1\
**Last updated:** [December 3, 2020, 1:31am UTC](https://discuss.elastic.co/t/security-solution-plugins-timestamp/257217 "2020-12-03T01:31:36Z")

</div>

Good Day, Just updated to 7.10 and while examining the kibana logs I find: {"type":"log","@timestamp":"2020-11-25T20:37:07Z","tags":\["error","plugins","securitySolution","plugins","securitySolution"\],"pid":22460,"messa…

---

## [SIEM - troubleshooting various error](https://discuss.elastic.co/t/siem-troubleshooting-various-error/257358)

<div class="topic-metadata">

**Author:** [@Colby99](https://discuss.elastic.co/u/Colby99)\
**Replies:** 1\
**Last updated:** [December 3, 2020, 1:27am UTC](https://discuss.elastic.co/t/siem-troubleshooting-various-error/257358 "2020-12-03T01:27:25Z")

</div>

Hello i have various error in the "Security" section. Starting by: The tab Overview: In the tab Hosts i got this 3 errors I'm using winlogbeat 7.10 and stack ELK 7.10 thank you for the help !

---

## [External alerts via API](https://discuss.elastic.co/t/external-alerts-via-api/257293)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 1\
**Last updated:** [December 2, 2020, 12:26pm UTC](https://discuss.elastic.co/t/external-alerts-via-api/257293 "2020-12-02T12:26:21Z")

</div>

Hi I am using the /detection\_engine/signals/search endpoint to grab detections but this endpoint doesn't include External alerts (eg. Crowdstrike). Is there an endpoint or other method to programmatically collect extern…

---

## [Just a question about a siem rule filter](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [November 30, 2020, 3:55pm UTC](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397 "2020-11-30T15:55:27Z")

</div>

Hello, Just wondering what's the purpose of the extra info / metadata in the filter of for example: I can't find this info in the SIEM rule when I duplicate it: { "$state": { "store": "appState" },…

---

## [Failed to close Detection alert](https://discuss.elastic.co/t/failed-to-close-detection-alert/256407)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [November 30, 2020, 2:53pm UTC](https://discuss.elastic.co/t/failed-to-close-detection-alert/256407 "2020-11-30T14:53:41Z")

</div>

Hello, Version 7.9.2 I was trying to clean up / close some old alerts and I get the following error: Known issue? In the Kibana logs I find a 409: Request referrer: https://kiburl:5601/app/security/detections?f…

---

## [Auditbeat not logging started process that run very short](https://discuss.elastic.co/t/auditbeat-not-logging-started-process-that-run-very-short/255877)

<div class="topic-metadata">

**Author:** [@bertr](https://discuss.elastic.co/u/bertr)\
**Replies:** 1\
**Last updated:** [November 29, 2020, 1:42pm UTC](https://discuss.elastic.co/t/auditbeat-not-logging-started-process-that-run-very-short/255877 "2020-11-29T13:42:55Z")

</div>

The process dataset of the system module of auditbeat does not register short running processes. (version = 7.8.1). E.g. cat of small file will not show up in auditbeat index, cat of a bigger file will. Both cat's do sho…

---

## [Detection rule for password spraying attempts](https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628)

<div class="topic-metadata">

**Author:** [@heading](https://discuss.elastic.co/u/heading)\
**Replies:** 2\
**Last updated:** [November 26, 2020, 2:18pm UTC](https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628 "2020-11-26T14:18:43Z")

</div>

Hi, we have a use case where we want to detect if a host tries to log on to a certain number of different users. With threshold rules we are only able to detect a specific number of login attempts by a host. We cannot e…

---

## ["Run now" action for SIEM rule](https://discuss.elastic.co/t/run-now-action-for-siem-rule/256526)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [November 24, 2020, 4:03pm UTC](https://discuss.elastic.co/t/run-now-action-for-siem-rule/256526 "2020-11-24T16:03:43Z")

</div>

Hello, Not sure if there is already a way to do this or if this is already on some to do list, but imho it would be super nice if we could trigger a "Run Now" on a rule. Let me know if this seems an interesting addit…

---

## [Security /Hosts / User Authentifications empty](https://discuss.elastic.co/t/security-hosts-user-authentifications-empty/253720)

<div class="topic-metadata">

**Author:** [@BenjaminD](https://discuss.elastic.co/u/BenjaminD)\
**Replies:** 5\
**Last updated:** [November 22, 2020, 8:36am UTC](https://discuss.elastic.co/t/security-hosts-user-authentifications-empty/253720 "2020-11-22T08:36:50Z")

</div>

Hi, I installed Elasticsearch 7.9.3 a few days ago on a server and then Winlogbeat on 4 other servers. In the User Authentifications section, it displays 0 from the beginning, regardless of the chosen time frame. Wh…

---

## [Filebeat Office 365 Failed getting a token](https://discuss.elastic.co/t/filebeat-office-365-failed-getting-a-token/256264)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [November 23, 2020, 12:58am UTC](https://discuss.elastic.co/t/filebeat-office-365-failed-getting-a-token/256264 "2020-11-23T00:58:53Z")

</div>

Hello, Configured the Filebet o365 module. Everything worked fine for some time, but last night things stopped working. The last event sent was: When I restart Filebeat, things start working again. Anyone an idea wh…

---

## [Enrich SIEM Data](https://discuss.elastic.co/t/enrich-siem-data/255749)

<div class="topic-metadata">

**Author:** [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Replies:** 1\
**Last updated:** [November 22, 2020, 8:10am UTC](https://discuss.elastic.co/t/enrich-siem-data/255749 "2020-11-22T08:10:55Z")

</div>

How to enrich SIEM data with Threat Intelligence? SIEM data can be overwhelming, how to implement Threat Intelligence feed like OTX Alienvault or other Intel feeds?

---

## [Eql query usage in watcher/siem detection rules](https://discuss.elastic.co/t/eql-query-usage-in-watcher-siem-detection-rules/255922)

<div class="topic-metadata">

**Author:** [@Akhil\_Mohan](https://discuss.elastic.co/u/Akhil_Mohan)\
**Replies:** 0\
**Last updated:** [November 19, 2020, 3:56am UTC](https://discuss.elastic.co/t/eql-query-usage-in-watcher-siem-detection-rules/255922 "2020-11-19T03:56:29Z")

</div>

EQL queries are available in elasticsearch 7.8 and later but we are not clear about how EQL queries are use in watcher/Siem detection rules.missing the documentation about same also. can you please instruct me how to us…

---

## [Extraction Elastic SIEM security events](https://discuss.elastic.co/t/extraction-elastic-siem-security-events/254927)

<div class="topic-metadata">

**Author:** [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Replies:** 5\
**Last updated:** [November 18, 2020, 8:38pm UTC](https://discuss.elastic.co/t/extraction-elastic-siem-security-events/254927 "2020-11-18T20:38:02Z")

</div>

Hi There, Is there a possibility of extracting all the raw documents of elasticsearch with respect to SIEM events . For example if we have rule name : \[Unusual Login Activity\] and we have enabled this particular out o…

---

## [Windows 2019: elastic-agent and endpoint security](https://discuss.elastic.co/t/windows-2019-elastic-agent-and-endpoint-security/255679)

<div class="topic-metadata">

**Author:** [@fausap](https://discuss.elastic.co/u/fausap)\
**Replies:** 0\
**Last updated:** [November 17, 2020, 11:36am UTC](https://discuss.elastic.co/t/windows-2019-elastic-agent-and-endpoint-security/255679 "2020-11-17T11:36:53Z")

</div>

Hello, I'm testing the endpoint-security feature through Elastic Agent. I was able to install and enroll the agent, but I have this error in the logs: {"log.level":"error","@timestamp":"2020-11-17T12:19:09.127+0100","l…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=13)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=15)
