# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=16

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 17

---

## [SIEM feature request](https://discuss.elastic.co/t/siem-feature-request/250340)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 4\
**Last updated:** [October 1, 2020, 11:22pm UTC](https://discuss.elastic.co/t/siem-feature-request/250340 "2020-10-01T23:22:36Z")

</div>

Hi, As i was scrolling down the huge pile of log and then i come up with this ideal for SIEM that i really want What i want is the ability to detect multiple event subsequently, what i mean is that for example i have a…

---

## [Calling Alerts from Watchers to detection Signals](https://discuss.elastic.co/t/calling-alerts-from-watchers-to-detection-signals/250032)

<div class="topic-metadata">

**Author:** [@Suro](https://discuss.elastic.co/u/Suro)\
**Replies:** 14\
**Last updated:** [October 1, 2020, 8:36am UTC](https://discuss.elastic.co/t/calling-alerts-from-watchers-to-detection-signals/250032 "2020-10-01T08:36:40Z")

</div>

Hi, We are running multiple watchers and as the SIEM detection does not provide the level of customizations, I have been unable to create use cases which takes aggregation for example under consideration. So I want to c…

---

## [Question on populating SIEM dashboard with winlogbeat data and Logstash](https://discuss.elastic.co/t/question-on-populating-siem-dashboard-with-winlogbeat-data-and-logstash/250510)

<div class="topic-metadata">

**Author:** [@Johan-p](https://discuss.elastic.co/u/Johan-p)\
**Replies:** 1\
**Last updated:** [September 30, 2020, 4:14pm UTC](https://discuss.elastic.co/t/question-on-populating-siem-dashboard-with-winlogbeat-data-and-logstash/250510 "2020-09-30T16:14:35Z")

</div>

Hi everyone, My company is setting up a Proof of Concept with Elastic SIEM. Running an on-prem setup: 3 Elastic nodes in a cluster configuration with one Kibana server and one Logstash server. While testing the SIEM d…

---

## [Packetbeat Rare DNS Questions ML Job Customization](https://discuss.elastic.co/t/packetbeat-rare-dns-questions-ml-job-customization/247548)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [September 29, 2020, 10:31am UTC](https://discuss.elastic.co/t/packetbeat-rare-dns-questions-ml-job-customization/247548 "2020-09-29T10:31:11Z")

</div>

Hello, I have an issue with the packetbeat rare dns question ml job, which generates quite a bit of anomalies due to the fact that our hosts are frequently contacting \*.avqs.mcafee.com url's, which have a random part. F…

---

## [SIEM detection rule apply for difference time](https://discuss.elastic.co/t/siem-detection-rule-apply-for-difference-time/249750)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [September 25, 2020, 2:15pm UTC](https://discuss.elastic.co/t/siem-detection-rule-apply-for-difference-time/249750 "2020-09-25T14:15:39Z")

</div>

Hi all I have a question regarding the SIEM detection, i have some windows log that are from 2019, and now when index them in to our elastic the @timestamp for it is 2019, now i want the detection engine to also search…

---

## [Elastic SIEM "Data Fetch Failure Invalid time value"](https://discuss.elastic.co/t/elastic-siem-data-fetch-failure-invalid-time-value/249388)

<div class="topic-metadata">

**Author:** [@soufiane\_adn](https://discuss.elastic.co/u/soufiane_adn)\
**Replies:** 5\
**Last updated:** [September 25, 2020, 2:07pm UTC](https://discuss.elastic.co/t/elastic-siem-data-fetch-failure-invalid-time-value/249388 "2020-09-25T14:07:54Z")

</div>

Hello guys, i hope you are doing well, so i'm facing a problem on the elastic siem app after parsing my logs and migrating them to ecs by logstash. the problem is the following error on the host/ event view : Data F…

---

## [Winlogbeat 7.9 not shipping logs in full ECS?](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411)

<div class="topic-metadata">

**Author:** [@AleksandrN](https://discuss.elastic.co/u/AleksandrN)\
**Replies:** 3\
**Last updated:** [September 24, 2020, 11:28am UTC](https://discuss.elastic.co/t/winlogbeat-7-9-not-shipping-logs-in-full-ecs/249411 "2020-09-24T11:28:56Z")

</div>

Hello everyone, I'mtrying to fill my Elastic SIEM with data, but it seems like Winlogbeat is not shipping logs in full ECS. For example, authentications wiget is empty: And it is formed by such default request: { …

---

## [Config alerts and actions email connector](https://discuss.elastic.co/t/config-alerts-and-actions-email-connector/249501)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 7\
**Last updated:** [September 24, 2020, 10:05am UTC](https://discuss.elastic.co/t/config-alerts-and-actions-email-connector/249501 "2020-09-24T10:05:35Z")

</div>

Hi all I wanted to try to config the mail sending feature for the SIEM, when i config the connector for email 2 encounter 2 problems: the username and password part every time i try to add new to it, when i save it t…

---

## [Elastic SIEM showing duplicate hosts when Defender ATP logs are shipped in](https://discuss.elastic.co/t/elastic-siem-showing-duplicate-hosts-when-defender-atp-logs-are-shipped-in/249152)

<div class="topic-metadata">

**Author:** [@InnerJoin](https://discuss.elastic.co/u/InnerJoin)\
**Replies:** 5\
**Last updated:** [September 23, 2020, 2:44pm UTC](https://discuss.elastic.co/t/elastic-siem-showing-duplicate-hosts-when-defender-atp-logs-are-shipped-in/249152 "2020-09-23T14:44:54Z")

</div>

I am currently working on getting together a POC of the Elastic SIEM solution. I already have a machine shipping logs into Elasticsearch with a winlogbeat agent and I am showing in the Hosts section of the SIEM that logs…

---

## [SIEM, Auditbeat Queries](https://discuss.elastic.co/t/siem-auditbeat-queries/249571)

<div class="topic-metadata">

**Author:** [@ckough](https://discuss.elastic.co/u/ckough)\
**Replies:** 0\
**Last updated:** [September 22, 2020, 5:42pm UTC](https://discuss.elastic.co/t/siem-auditbeat-queries/249571 "2020-09-22T17:42:16Z")

</div>

Hi there, I am trying out Elastic Siem 7.7 with Auditbeat 7.7 on Red Hat 7.6 and I have a few questions. Is SIEM data available only when I set Auditbeat output to elasticsearch? I try output to logstash-\>elasticsearc…

---

## [Elastic siem receive another Security Device log](https://discuss.elastic.co/t/elastic-siem-receive-another-security-device-log/249318)

<div class="topic-metadata">

**Author:** [@111387](https://discuss.elastic.co/u/111387)\
**Replies:** 1\
**Last updated:** [September 21, 2020, 3:24pm UTC](https://discuss.elastic.co/t/elastic-siem-receive-another-security-device-log/249318 "2020-09-21T15:24:28Z")

</div>

I Want to Using IPS, Anti Virus etc.. log in Elastic Siem is it possible using this log??? i want security log to logstash -\> ElasticSiem and make Correlation rules

---

## [Filebeat not picking up OSQUERY LOGS](https://discuss.elastic.co/t/filebeat-not-picking-up-osquery-logs/249279)

<div class="topic-metadata">

**Author:** [@Vansh\_Kumar\_Madan](https://discuss.elastic.co/u/Vansh_Kumar_Madan)\
**Replies:** 0\
**Last updated:** [September 20, 2020, 7:21pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-osquery-logs/249279 "2020-09-20T19:21:34Z")

</div>

Hi, I am trying to intergate filbeat osquey module, my osquery is running successfully, and logs are building up at path /var/log/osquery/osqueryd.results.log I am passing this path in filebeat osquery module osquery.…

---

## [SIEM detection engine is not getting started](https://discuss.elastic.co/t/siem-detection-engine-is-not-getting-started/248910)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 12\
**Last updated:** [September 20, 2020, 12:52pm UTC](https://discuss.elastic.co/t/siem-detection-engine-is-not-getting-started/248910 "2020-09-20T12:52:04Z")

</div>

I have installed stack on AWS, all three(Elastic, Logstash, Kibana) components are on different instance. Stack is running all good and functioning in a expected way. Problem is, I am unable to enable detection engine, …

---

## [SIEM Hosts/All Hosts Tables Empty](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/248965)

<div class="topic-metadata">

**Author:** [@Dan\_Sputnikk](https://discuss.elastic.co/u/Dan_Sputnikk)\
**Replies:** 2\
**Last updated:** [September 19, 2020, 4:07am UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/248965 "2020-09-19T04:07:00Z")

</div>

Hi all, Configured filebeat 7.9 against ES/Kibana 7.9 and the netflow + cisco modules successfully and without errors, including during template generation. http s://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-…

---

## [(ELK 7.9.1) Security - Hosts and Security - Network missing data](https://discuss.elastic.co/t/elk-7-9-1-security-hosts-and-security-network-missing-data/248576)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 19\
**Last updated:** [September 17, 2020, 10:19pm UTC](https://discuss.elastic.co/t/elk-7-9-1-security-hosts-and-security-network-missing-data/248576 "2020-09-17T22:19:57Z")

</div>

Hi, \*Recently upgraded to ELK 7.9.1. \*All beats were upgraded to match same node version \*All indexes were deleted and recreated As stated above, I am running ELK 7.9.1. If I check Discovery section, I can confirm th…

---

## [Limit CPU/Memory usage in Auditbeat & Filebeats , version 7.9.0](https://discuss.elastic.co/t/limit-cpu-memory-usage-in-auditbeat-filebeats-version-7-9-0/248231)

<div class="topic-metadata">

**Author:** [@ajesh](https://discuss.elastic.co/u/ajesh)\
**Replies:** 7\
**Last updated:** [September 17, 2020, 1:23pm UTC](https://discuss.elastic.co/t/limit-cpu-memory-usage-in-auditbeat-filebeats-version-7-9-0/248231 "2020-09-17T13:23:10Z")

</div>

Hi Team, We are seeing that auditbeat service is using lot of memory in our VM's , we suspect that when elasticsearch cluster is down its taking more memory in auditbeat to buffer the data. Could you please let me know …

---

## [Error activating rule…](https://discuss.elastic.co/t/error-activating-rule/248424)

<div class="topic-metadata">

**Author:** [@Akash\_Upadhyay](https://discuss.elastic.co/u/Akash_Upadhyay)\
**Replies:** 8\
**Last updated:** [September 15, 2020, 10:11pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424 "2020-09-15T22:11:49Z")

</div>

Hey, I have installed elk using docker. It is up and running fine. But the problem occurs when I try to activate pre-built rules. My docker-compose.yml configurations are: version: '3' services: elasticsearch: …

---

## [Parsing o365.audit.Data filed for o365 Module](https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370)

<div class="topic-metadata">

**Author:** [@opiedrah](https://discuss.elastic.co/u/opiedrah)\
**Replies:** 2\
**Last updated:** [September 14, 2020, 6:21pm UTC](https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370 "2020-09-14T18:21:00Z")

</div>

Hi folks, I've had the o365 module for Filebeat working for a while. I've onboarded a new workload called: o365.audit.Workload :"AirInvestigation" The filed is composed of nested json objects just the same as the Ext…

---

## [Unable to load ASA logs in SIEM](https://discuss.elastic.co/t/unable-to-load-asa-logs-in-siem/247977)

<div class="topic-metadata">

**Author:** [@Kupauw](https://discuss.elastic.co/u/Kupauw)\
**Replies:** 1\
**Last updated:** [September 9, 2020, 9:22am UTC](https://discuss.elastic.co/t/unable-to-load-asa-logs-in-siem/247977 "2020-09-09T09:22:24Z")

</div>

Hi everyone. Last week i set up a filebeat (7.8.1) to ingest syslog from an Cisco ASA. Everything works fine and the data is visible in kibana. Now when i go to the SIEM page and try to setup SIEM with the Cisco module…

---

## [Siem Rule to detect ssh login with multiple source address](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718)

<div class="topic-metadata">

**Author:** [@Kambing](https://discuss.elastic.co/u/Kambing)\
**Replies:** 2\
**Last updated:** [September 9, 2020, 8:23am UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718 "2020-09-09T08:23:04Z")

</div>

Hi, I'm new with Elastic SIEM and now I need to create a rule to detect ssh successful login with multiple IP address with the same username. I wonder how can I create a rule like this since if I using Custon Query or Th…

---

## [Threat Hunting Report for Elasticsearch](https://discuss.elastic.co/t/threat-hunting-report-for-elasticsearch/246540)

<div class="topic-metadata">

**Author:** [@syafeera](https://discuss.elastic.co/u/syafeera)\
**Replies:** 10\
**Last updated:** [September 9, 2020, 1:25am UTC](https://discuss.elastic.co/t/threat-hunting-report-for-elasticsearch/246540 "2020-09-09T01:25:13Z")

</div>

Hi there, Did anyone here know how to do Threat Hunting report using SIEM in Kibana?

---

## [Authentications tab shows "All values returned zero"](https://discuss.elastic.co/t/authentications-tab-shows-all-values-returned-zero/240784)

<div class="topic-metadata">

**Author:** [@xhidalgo](https://discuss.elastic.co/u/xhidalgo)\
**Replies:** 14\
**Last updated:** [September 8, 2020, 6:22am UTC](https://discuss.elastic.co/t/authentications-tab-shows-all-values-returned-zero/240784 "2020-09-08T06:22:22Z")

</div>

Hi, I'm using Elastic Cloud, I have two different deployments. One in version 7.6.2 and Elastic SIEM it's working properly and one in 7.8.0 In this last version 7.8.0 , SIEM Module don't show authentications even when…

---

## [Journalbeat in Elastic SIEM](https://discuss.elastic.co/t/journalbeat-in-elastic-siem/247305)

<div class="topic-metadata">

**Author:** [@Alfredo1](https://discuss.elastic.co/u/Alfredo1)\
**Replies:** 1\
**Last updated:** [September 3, 2020, 12:17pm UTC](https://discuss.elastic.co/t/journalbeat-in-elastic-siem/247305 "2020-09-03T12:17:02Z")

</div>

I recently started consuming HashiCorp Vault (secrets manager) audit logs into my cluster via Journalbeat, and while it's great to view the logs in Discover, it would be useful to surface those logs and associated metric…

---

## [Feature Request: Alert Assignment to user](https://discuss.elastic.co/t/feature-request-alert-assignment-to-user/247095)

<div class="topic-metadata">

**Author:** [@madduck](https://discuss.elastic.co/u/madduck)\
**Replies:** 1\
**Last updated:** [September 2, 2020, 5:49pm UTC](https://discuss.elastic.co/t/feature-request-alert-assignment-to-user/247095 "2020-09-02T17:49:45Z")

</div>

Hello, playing around more and more with the SIEM and signals etc. and I saw that there does not seem to be a way to assign signals. I can mark them as "open", "in progress" or "done" however I have no information whic…

---

## [Feedback: Cases](https://discuss.elastic.co/t/feedback-cases/247101)

<div class="topic-metadata">

**Author:** [@madduck](https://discuss.elastic.co/u/madduck)\
**Replies:** 1\
**Last updated:** [September 2, 2020, 12:59pm UTC](https://discuss.elastic.co/t/feedback-cases/247101 "2020-09-02T12:59:59Z")

</div>

Hello, its me again, took a look at Cases, saw they are still in Beta, thought I'd share some feedback. No option to lock a case At the moment it is not possible to lock a case from other users. This can be helpful if…

---

## [SIEM Threshold - unique values](https://discuss.elastic.co/t/siem-threshold-unique-values/246606)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 5\
**Last updated:** [September 1, 2020, 3:18pm UTC](https://discuss.elastic.co/t/siem-threshold-unique-values/246606 "2020-09-01T15:18:33Z")

</div>

Hi I am playing with the SIEM capability and have been using it since it was released with custom queries. I am now looking at Threshold based detection in v7.9 - something I think will be very useful. I'm not sure if…

---

## [No TLS details](https://discuss.elastic.co/t/no-tls-details/222593)

<div class="topic-metadata">

**Author:** [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Replies:** 2\
**Last updated:** [August 31, 2020, 8:54pm UTC](https://discuss.elastic.co/t/no-tls-details/222593 "2020-08-31T20:54:11Z")

</div>

See also attached image: While there seem to be thousands of TLS handshakes, the SIEM-network table with TLS details is empty. The Packetbeat config details: - type: tls # Configure the ports where to listen for T…

---

## [Value list entries as a trigger instead of exception](https://discuss.elastic.co/t/value-list-entries-as-a-trigger-instead-of-exception/246747)

<div class="topic-metadata">

**Author:** [@madduck](https://discuss.elastic.co/u/madduck)\
**Replies:** 2\
**Last updated:** [August 28, 2020, 6:35pm UTC](https://discuss.elastic.co/t/value-list-entries-as-a-trigger-instead-of-exception/246747 "2020-08-28T18:35:39Z")

</div>

Hi gang, is it possible to use value list as anything other than an exception? I have a list of Command and Control servers and would like to get a signal every time an ip address from that value list is part of "desti…

---

## [Detection engine permission issues after upgrade to 7.9](https://discuss.elastic.co/t/detection-engine-permission-issues-after-upgrade-to-7-9/246407)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 2\
**Last updated:** [August 26, 2020, 10:41am UTC](https://discuss.elastic.co/t/detection-engine-permission-issues-after-upgrade-to-7-9/246407 "2020-08-26T10:41:57Z")

</div>

Hi, Yesterday we have upgraded our cluster to 7.9 and users are reporting problems with the Detection tab in SIEM app. When opened they get "Let's set up your detection engine" message. The role assigned to the users h…

---

## [Unsynchronized time in Elasticsearch](https://discuss.elastic.co/t/unsynchronized-time-in-elasticsearch/246083)

<div class="topic-metadata">

**Author:** [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)\
**Replies:** 2\
**Last updated:** [August 26, 2020, 8:28am UTC](https://discuss.elastic.co/t/unsynchronized-time-in-elasticsearch/246083 "2020-08-26T08:28:20Z")

</div>

Hi Today when I created a rule in SIEM the "last run" field showed "in 3 hours". after some digging, I found that the clock in the ELK machine(single node cluster, centos 7) was behind. I correct it using ntp and now wh…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=15)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=17)
