# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=15

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 16

---

## [Threat Intel and SIEM](https://discuss.elastic.co/t/threat-intel-and-siem/255404)

<div class="topic-metadata">

**Author:** [@randomguy](https://discuss.elastic.co/u/randomguy)\
**Replies:** 2\
**Last updated:** [November 17, 2020, 10:27am UTC](https://discuss.elastic.co/t/threat-intel-and-siem/255404 "2020-11-17T10:27:10Z")

</div>

Hi, I'm looking for a SIEM solution for our company. At the moment I'm trying to do it with ELK. My goal is: I would like to create fancy dashboards, alerts with events correlated from Threat Intel. I would like to u…

---

## [Signal - multiple login failure from same user](https://discuss.elastic.co/t/signal-multiple-login-failure-from-same-user/255517)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 1\
**Last updated:** [November 16, 2020, 12:24pm UTC](https://discuss.elastic.co/t/signal-multiple-login-failure-from-same-user/255517 "2020-11-16T12:24:57Z")

</div>

Please help me to create a signal for below logic. Alert if there is more than 3 login failure from same user in last 5min. I have mentioned below the watcher query written for same above logic. “query”: { “bool”: { …

---

## [Compare two fields in SIEM](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927)

<div class="topic-metadata">

**Author:** [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Replies:** 13\
**Last updated:** [November 16, 2020, 11:50am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927 "2020-11-16T11:50:59Z")

</div>

Hi, I want to trigger an alarm if two fields have the same value. is it possible or I have to use watcher?

---

## [Conditional query for SIEM](https://discuss.elastic.co/t/conditional-query-for-siem/255330)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [November 16, 2020, 6:03am UTC](https://discuss.elastic.co/t/conditional-query-for-siem/255330 "2020-11-16T06:03:50Z")

</div>

Hi all I have some ability that i require SIEM do. i want to make a query and then if that query match then the second query will be call to search for that specific case since not all security case that happen in sing…

---

## [Customize Detection Columns?](https://discuss.elastic.co/t/customize-detection-columns/254455)

<div class="topic-metadata">

**Author:** [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Replies:** 10\
**Last updated:** [November 13, 2020, 9:14pm UTC](https://discuss.elastic.co/t/customize-detection-columns/254455 "2020-11-13T21:14:01Z")

</div>

Is it possible to customize the columns in the detections alerts view? I'd like to incorporate some fields from the underlying events, if possible.

---

## [Question on the capability of elastic SIEM](https://discuss.elastic.co/t/question-on-the-capability-of-elastic-siem/254843)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [November 10, 2020, 7:10pm UTC](https://discuss.elastic.co/t/question-on-the-capability-of-elastic-siem/254843 "2020-11-10T19:10:02Z")

</div>

Hi all I have a question on how extent SIEM can query for data. Can siem query for regex data like the api can.

---

## [Ingesting from AWS & Azzure](https://discuss.elastic.co/t/ingesting-from-aws-azzure/254877)

<div class="topic-metadata">

**Author:** [@darkbeatz](https://discuss.elastic.co/u/darkbeatz)\
**Replies:** 1\
**Last updated:** [November 10, 2020, 4:40pm UTC](https://discuss.elastic.co/t/ingesting-from-aws-azzure/254877 "2020-11-10T16:40:22Z")

</div>

Hi All Just wondering if people are collecting logs from AWS or Azure and sending to elastic SIEM? Guard duty, cloudtrail etc.. How have you achieved this if so?

---

## [Building block rules/use case](https://discuss.elastic.co/t/building-block-rules-use-case/254737)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 7\
**Last updated:** [November 10, 2020, 9:13am UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737 "2020-11-10T09:13:40Z")

</div>

Hi, I am trying to understand the building block rules. Should we be able to create a rule that triggers if multiple building block rules trigger? If so how would I go about it? Thanks Phil

---

## [SIEM feature request](https://discuss.elastic.co/t/siem-feature-request/254504)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [November 10, 2020, 2:51am UTC](https://discuss.elastic.co/t/siem-feature-request/254504 "2020-11-10T02:51:13Z")

</div>

Hi all, i have noticed that the api search in elastic using the console is really fast compare to how the kibana search. I was wondering if there is any difference in how kibana KQL search with the text box and the api …

---

## [SIEM rule not working for custom query](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895)

<div class="topic-metadata">

**Author:** [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Replies:** 6\
**Last updated:** [November 9, 2020, 3:38pm UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895 "2020-11-09T15:38:49Z")

</div>

HI, I'm trying to create a simple rule that checks host.name field: But no signal is generating. here is my index mapping. I can see events in timeline using the same query.

---

## [SIEM Signals not triggering](https://discuss.elastic.co/t/siem-signals-not-triggering/254151)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 10\
**Last updated:** [November 9, 2020, 12:50pm UTC](https://discuss.elastic.co/t/siem-signals-not-triggering/254151 "2020-11-09T12:50:07Z")

</div>

SIEM signals are not triggering even after the events are generated. But same KQL query used in signal is working fine in discover tab. Please help me to resolve this issue.

---

## [Custom SIEM rules: illegal\_argument\_exception permission issue](https://discuss.elastic.co/t/custom-siem-rules-illegal-argument-exception-permission-issue/253787)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 5\
**Last updated:** [November 6, 2020, 11:34pm UTC](https://discuss.elastic.co/t/custom-siem-rules-illegal-argument-exception-permission-issue/253787 "2020-11-06T23:34:27Z")

</div>

I've created a custom rule, which seems working if I run via the console. But when I put it as a SIEM rule, below error occurs Any idea which permission/privilege I need to do to fix the issue? An error occurred during…

---

## [SIEM rule override not working as expected](https://discuss.elastic.co/t/siem-rule-override-not-working-as-expected/253933)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [November 4, 2020, 12:55pm UTC](https://discuss.elastic.co/t/siem-rule-override-not-working-as-expected/253933 "2020-11-04T12:55:22Z")

</div>

Hello, Recently tried to use the severity overrides functionality for a SIEM rule, but this doesn't seem to work as expected. While trying to find what's going wrong I'd like to point out several things: When editing…

---

## [Cant sent mail upon SIEM alert](https://discuss.elastic.co/t/cant-sent-mail-upon-siem-alert/253517)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 2\
**Last updated:** [November 3, 2020, 1:31am UTC](https://discuss.elastic.co/t/cant-sent-mail-upon-siem-alert/253517 "2020-11-03T01:31:18Z")

</div>

Hi all I have some problems with the alert and action with siem part i have config the alert and action to exacly like our watcher ( watcher worked ) I have turned on the xpack.eventLog.logEntries to true when i set …

---

## [Detections with custom query](https://discuss.elastic.co/t/detections-with-custom-query/252628)

<div class="topic-metadata">

**Author:** [@Anirudhan](https://discuss.elastic.co/u/Anirudhan)\
**Replies:** 14\
**Last updated:** [October 30, 2020, 4:40pm UTC](https://discuss.elastic.co/t/detections-with-custom-query/252628 "2020-10-30T16:40:38Z")

</div>

Hi In the detections, rules created a custom rule for my own index. A simple match query is not working, but the same rule is working with an aggregate query.! detections|690x283 The rule with custom query externalId:…

---

## [TLS Information](https://discuss.elastic.co/t/tls-information/253794)

<div class="topic-metadata">

**Author:** [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Replies:** 3\
**Last updated:** [October 30, 2020, 11:10am UTC](https://discuss.elastic.co/t/tls-information/253794 "2020-10-30T11:10:11Z")

</div>

Hi Team! What are the integration tools ( beats family etc ) required to we collect certificates data from session connections to identify TLS Version, Ciphers, Valid until, Issuer, Subject, fingerprint etc from a host …

---

## [Index patterns global and per rule?](https://discuss.elastic.co/t/index-patterns-global-and-per-rule/253109)

<div class="topic-metadata">

**Author:** [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Replies:** 2\
**Last updated:** [October 27, 2020, 12:44pm UTC](https://discuss.elastic.co/t/index-patterns-global-and-per-rule/253109 "2020-10-27T12:44:59Z")

</div>

Hi, I know, that I have to set in Stack Management/Kibana/Advanced which Indices are considered when SIEM is doing it's magic. But I just recently realised there are another "index patterns" per rule. Are these mere re…

---

## [Detection Rule Error](https://discuss.elastic.co/t/detection-rule-error/252856)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 5\
**Last updated:** [October 27, 2020, 5:04am UTC](https://discuss.elastic.co/t/detection-rule-error/252856 "2020-10-27T05:04:26Z")

</div>

Hi, I'm running the 7.9.2 version of the stack in a hot-warm cluster architecture. When defining a very simple detection rule on my space called "siem" I get the following error intermittently. One execution succeed an…

---

## [SIEM Threshold Based Rules - Show several fields value](https://discuss.elastic.co/t/siem-threshold-based-rules-show-several-fields-value/253385)

<div class="topic-metadata">

**Author:** [@Kambing](https://discuss.elastic.co/u/Kambing)\
**Replies:** 0\
**Last updated:** [October 27, 2020, 4:41am UTC](https://discuss.elastic.co/t/siem-threshold-based-rules-show-several-fields-value/253385 "2020-10-27T04:41:16Z")

</div>

Hi, I already create threshold based detection and it was successfully detected. But I realize it only has specific fields to display and is different from Query based detection which contain all fields when the rules tr…

---

## [RDP from Internet rule triggering on bogon ip address](https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [October 26, 2020, 10:53am UTC](https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269 "2020-10-26T10:53:32Z")

</div>

Hello, Noticed the SIEM rule" RDP (Remote Desktop Protocol) from the Internet" triggered on source.ip: "169.254.231.41" which is a bogon link-local address. So this should not be considered as "from the Internet" and…

---

## [Detections is adding 20-30 minutes to my @timestamp](https://discuss.elastic.co/t/detections-is-adding-20-30-minutes-to-my-timestamp/252401)

<div class="topic-metadata">

**Author:** [@Junebee](https://discuss.elastic.co/u/Junebee)\
**Replies:** 2\
**Last updated:** [October 22, 2020, 12:53pm UTC](https://discuss.elastic.co/t/detections-is-adding-20-30-minutes-to-my-timestamp/252401 "2020-10-22T12:53:01Z")

</div>

I am a long time user of ELK and recently switched to 7.9 to experiment with Security and SIEM functions. After much trouble shooting to get my test Detection to show up in the "Detection Alerts" area, I discovered by …

---

## [Elastic siem overview dashboard config](https://discuss.elastic.co/t/elastic-siem-overview-dashboard-config/252916)

<div class="topic-metadata">

**Author:** [@111387](https://discuss.elastic.co/u/111387)\
**Replies:** 1\
**Last updated:** [October 22, 2020, 1:20am UTC](https://discuss.elastic.co/t/elastic-siem-overview-dashboard-config/252916 "2020-10-22T01:20:34Z")

</div>

Hello. I recevied suricata and other security solution logs with filebeat and send to Elastic Siem Is it possible to edit the list in the Network Event, Host Event menu in SIEM's Overview Tab?? I don't use Auditbeat a…

---

## [Cannot filter data in elastic SIEM](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 5\
**Last updated:** [October 20, 2020, 10:47pm UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124 "2020-10-20T22:47:29Z")

</div>

Hi all I have a problems in the elastic siem. The filter function for me when i tried to filter for some field in the rule that i have created. those field seems to be not recognized by elastic so they do not allow me …

---

## [SIEM error unexpected token \<in JSON at position 0](https://discuss.elastic.co/t/siem-error-unexpected-token-in-json-at-position-0/252327)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 5\
**Last updated:** [October 20, 2020, 10:44pm UTC](https://discuss.elastic.co/t/siem-error-unexpected-token-in-json-at-position-0/252327 "2020-10-20T22:44:59Z")

</div>

Hi all I currently have a very anoying problems Everytime i went to SIEM app, they load for sometime and then the system popup a error unexpected token \<in JSON at position 0 like 2 time, one for network error and one …

---

## [Adding screenshots to cases](https://discuss.elastic.co/t/adding-screenshots-to-cases/251556)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 4\
**Last updated:** [October 20, 2020, 3:38pm UTC](https://discuss.elastic.co/t/adding-screenshots-to-cases/251556 "2020-10-20T15:38:17Z")

</div>

Hello, An awesome enhancement to SIEM would be the ability to paste screenshots in the created cases. Although the timeline is a handy thing, a quick screenshot makes things a lot more clear. Is this a feature that woul…

---

## [EQL: Why basic query is different from dataset](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 5\
**Last updated:** [October 15, 2020, 9:14pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242 "2020-10-15T21:14:45Z")

</div>

I'm running a simple EQL query to test as follows, but NOT reporting anything back GET winlogbeat\*/\_eql/search { "query": """ process where process.name == "services.exe" """ } Quite lot of data is present and If…

---

## [Elastic SIEM](https://discuss.elastic.co/t/elastic-siem/251784)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 5\
**Last updated:** [October 14, 2020, 9:04pm UTC](https://discuss.elastic.co/t/elastic-siem/251784 "2020-10-14T21:04:24Z")

</div>

I am having issues starting the ML datafeeds for SIEM, I've tried manually putting in a mapping for @timestamp as date but i still get this error anyone else have this issue ? \` "{"error":{"root\_cause":\[{"type":"status…

---

## [Elastic 7.9.1 - Security (SIEM) - Your visualization has error(s) - \[illegal\_argument\_exception\]](https://discuss.elastic.co/t/elastic-7-9-1-security-siem-your-visualization-has-error-s-illegal-argument-exception/250265)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 15\
**Last updated:** [October 12, 2020, 8:05pm UTC](https://discuss.elastic.co/t/elastic-7-9-1-security-siem-your-visualization-has-error-s-illegal-argument-exception/250265 "2020-10-12T20:05:40Z")

</div>

Hi, We have a brand new cluster install to test 7.9.1 and the security features in particular. When navigating to the Overview page we get the following error. \[illegal\_argument\_exception\] Text fields are not optimise…

---

## [Going from detection page to rule page in 1 click](https://discuss.elastic.co/t/going-from-detection-page-to-rule-page-in-1-click/251636)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [October 12, 2020, 4:10pm UTC](https://discuss.elastic.co/t/going-from-detection-page-to-rule-page-in-1-click/251636 "2020-10-12T16:10:10Z")

</div>

Hello, Just an idea (which might already be on some roadmap). It would save us a lot of time if we could go from the Detections page straight to the rule page. This could be done for example by adding a button to: Cu…

---

## [Threshold rules not triggering on selfmade index](https://discuss.elastic.co/t/threshold-rules-not-triggering-on-selfmade-index/251029)

<div class="topic-metadata">

**Author:** [@madduck](https://discuss.elastic.co/u/madduck)\
**Replies:** 15\
**Last updated:** [October 9, 2020, 12:49pm UTC](https://discuss.elastic.co/t/threshold-rules-not-triggering-on-selfmade-index/251029 "2020-10-09T12:49:13Z")

</div>

Hello, I am currently trying to create a simple threshold rule that should trigger after x amounts of failed logons. The issue here is that the rule does not trigger at all, not even when the threshold is set to 1. Th…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=14)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=16)
