# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=17

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 18

---

## [Can not get network sockets info](https://discuss.elastic.co/t/can-not-get-network-sockets-info/245398)

<div class="topic-metadata">

**Author:** [@ali.al-janabi](https://discuss.elastic.co/u/ali.al-janabi)\
**Replies:** 7\
**Last updated:** [August 25, 2020, 3:57pm UTC](https://discuss.elastic.co/t/can-not-get-network-sockets-info/245398 "2020-08-25T15:57:55Z")

</div>

Hello, I'm deploying elasticsearch SIEM using auditbeat and having trouble to get the network sockets counts, open, closed information. they all show 0 value in the network socket dashboard. in my deployment, I have el…

---

## [ELK SIEM](https://discuss.elastic.co/t/elk-siem/246234)

<div class="topic-metadata">

**Author:** [@Deepika\_Rawat](https://discuss.elastic.co/u/Deepika_Rawat)\
**Replies:** 3\
**Last updated:** [August 25, 2020, 12:49pm UTC](https://discuss.elastic.co/t/elk-siem/246234 "2020-08-25T12:49:21Z")

</div>

Is Elk SIEM free ?? and how can i import data in siem through logstash i just wanted to check its functionality as a threat analyst.I am looking and comparing more options but since i am familiar with logstash and filebe…

---

## [Sophos module not working](https://discuss.elastic.co/t/sophos-module-not-working/245629)

<div class="topic-metadata">

**Author:** [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Replies:** 3\
**Last updated:** [August 24, 2020, 8:13am UTC](https://discuss.elastic.co/t/sophos-module-not-working/245629 "2020-08-24T08:13:23Z")

</div>

So I have been waiting for the Sophos XG module for some time since we use Sophos XG FW and when I got to know that 7.9 was released I quickly updated my filebeat and tried setting up the ingest pipeline for sophos but t…

---

## [Signal detection ML rule not working](https://discuss.elastic.co/t/signal-detection-ml-rule-not-working/245984)

<div class="topic-metadata">

**Author:** [@SUNILKUMAR\_BATANA](https://discuss.elastic.co/u/SUNILKUMAR_BATANA)\
**Replies:** 0\
**Last updated:** [August 22, 2020, 12:01pm UTC](https://discuss.elastic.co/t/signal-detection-ml-rule-not-working/245984 "2020-08-22T12:01:15Z")

</div>

Hi, I tried to create a ML rule for detecting signals when there is an anomaly in a ML job. The ML job is clearly showing anomalies but the rule is not detecting signals. Further, the rule is getting executed successf…

---

## [Auditbeat compared to Winlogbeat, Metricbeat](https://discuss.elastic.co/t/auditbeat-compared-to-winlogbeat-metricbeat/244779)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 4\
**Last updated:** [August 19, 2020, 7:50pm UTC](https://discuss.elastic.co/t/auditbeat-compared-to-winlogbeat-metricbeat/244779 "2020-08-19T19:50:23Z")

</div>

On Windows Auditbeat the system module exposes the host and processes datasets. In this setup the file integrity module is not used. On the same MS servers Winlogbeat with the security module as well as Metricbeat and Pa…

---

## [Import rules from public detection rules repo](https://discuss.elastic.co/t/import-rules-from-public-detection-rules-repo/245344)

<div class="topic-metadata">

**Author:** [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)\
**Replies:** 2\
**Last updated:** [August 18, 2020, 7:39pm UTC](https://discuss.elastic.co/t/import-rules-from-public-detection-rules-repo/245344 "2020-08-18T19:39:32Z")

</div>

Hi I want to import new rules from the repo but the rule's format is json or toml but SIEM only accepts ndjson files. should i manually convert them? is there a tool you recommend?

---

## [Visualizations has errors default page](https://discuss.elastic.co/t/visualizations-has-errors-default-page/245176)

<div class="topic-metadata">

**Author:** [@bevano](https://discuss.elastic.co/u/bevano)\
**Replies:** 5\
**Last updated:** [August 18, 2020, 2:09am UTC](https://discuss.elastic.co/t/visualizations-has-errors-default-page/245176 "2020-08-18T02:09:39Z")

</div>

Hi All, Just started to play around with SIEM. When opening the menu, we are constantly presented with this error. The only logs we are ingesting is our building security logs, and I have manually created logstash filte…

---

## [Some Kibana SIEM feature not working with arrays](https://discuss.elastic.co/t/some-kibana-siem-feature-not-working-with-arrays/245029)

<div class="topic-metadata">

**Author:** [@obuez](https://discuss.elastic.co/u/obuez)\
**Replies:** 3\
**Last updated:** [August 17, 2020, 7:10pm UTC](https://discuss.elastic.co/t/some-kibana-siem-feature-not-working-with-arrays/245029 "2020-08-17T19:10:13Z")

</div>

Hi All, To be able to use the Elastic SIEM feature with our own data, we have decided to be ECS compliant regarding the values (IP,... ) but also the enrichment values (AS name,... ). We are doing the enrichment our-sel…

---

## [SIEM not show country flag](https://discuss.elastic.co/t/siem-not-show-country-flag/244960)

<div class="topic-metadata">

**Author:** [@Luan\_Ph\_m](https://discuss.elastic.co/u/Luan_Ph_m)\
**Replies:** 1\
**Last updated:** [August 17, 2020, 2:13pm UTC](https://discuss.elastic.co/t/siem-not-show-country-flag/244960 "2020-08-17T14:13:11Z")

</div>

Hi I have an issue with SIEM app, my SIEM not show country flag. Here my screenshot Thanks

---

## [Multi-tenancy with Elastic SIEM detection rules](https://discuss.elastic.co/t/multi-tenancy-with-elastic-siem-detection-rules/244548)

<div class="topic-metadata">

**Author:** [@admlko](https://discuss.elastic.co/u/admlko)\
**Replies:** 4\
**Last updated:** [August 13, 2020, 8:35am UTC](https://discuss.elastic.co/t/multi-tenancy-with-elastic-siem-detection-rules/244548 "2020-08-13T08:35:03Z")

</div>

Hi, Multi-tenancy can be easily gained with ML detection rules using partition field. Just partition based on the field containing customer id. Could this same approach be used with SIEM detection rules? If I have und…

---

## [WHAT SIEM CAN DO?](https://discuss.elastic.co/t/what-siem-can-do/244483)

<div class="topic-metadata">

**Author:** [@syafeera](https://discuss.elastic.co/u/syafeera)\
**Replies:** 3\
**Last updated:** [August 13, 2020, 6:56am UTC](https://discuss.elastic.co/t/what-siem-can-do/244483 "2020-08-13T06:56:27Z")

</div>

Hi, is there anyone here can explain to me a simple way what is SIEM? How can SIEM detect threat? what is IP destination and IP source means in SIEM? I really not clear about it.. Thanks

---

## [Signal Timestamp Issue](https://discuss.elastic.co/t/signal-timestamp-issue/244669)

<div class="topic-metadata">

**Author:** [@Saurabh\_Singh1](https://discuss.elastic.co/u/Saurabh_Singh1)\
**Replies:** 1\
**Last updated:** [August 13, 2020, 4:18am UTC](https://discuss.elastic.co/t/signal-timestamp-issue/244669 "2020-08-13T04:18:11Z")

</div>

Hi All, I am trying the following scenario: 1.) Trying to ingest data into index in IST format. 2.) Created a detection rule over the index. 3.) Signals are getting generated. Observ…

---

## [Panw module (Palo Alto) ingest reports Object Object.getClass() error because receiver is null](https://discuss.elastic.co/t/panw-module-palo-alto-ingest-reports-object-object-getclass-error-because-receiver-is-null/244747)

<div class="topic-metadata">

**Author:** [@srpine](https://discuss.elastic.co/u/srpine)\
**Replies:** 1\
**Last updated:** [August 12, 2020, 6:36pm UTC](https://discuss.elastic.co/t/panw-module-palo-alto-ingest-reports-object-object-getclass-error-because-receiver-is-null/244747 "2020-08-12T18:36:34Z")

</div>

I am seeing errors for some of the TRAFFIC entries in the log. Pipeline complains about: Object Object.getClass() because receiver is null After breaking down the csv I found the following fields 12,13,19 were null in…

---

## [Excessive "External Alerts" after update to 7.8](https://discuss.elastic.co/t/excessive-external-alerts-after-update-to-7-8/244428)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [August 11, 2020, 2:49pm UTC](https://discuss.elastic.co/t/excessive-external-alerts-after-update-to-7-8/244428 "2020-08-11T14:49:02Z")

</div>

Hello, Updated to 7.8.1 last week and just noticed that we have a huge amount of external alerts now from panw.panos. I've been working on updating event.kind to alert for mcafee and cylance logs, but that's kind of …

---

## [Using Elastic SIEM and ML with Beats and Logstash](https://discuss.elastic.co/t/using-elastic-siem-and-ml-with-beats-and-logstash/242560)

<div class="topic-metadata">

**Author:** [@chancewwr](https://discuss.elastic.co/u/chancewwr)\
**Replies:** 12\
**Last updated:** [August 10, 2020, 10:16pm UTC](https://discuss.elastic.co/t/using-elastic-siem-and-ml-with-beats-and-logstash/242560 "2020-08-10T22:16:04Z")

</div>

Hello all. My question is what is the general method for using beats with logstash if you want access to Elastic SIEM and the like? Elastic SIEM works well when the data is gathered via beats and sent directly to Elasti…

---

## [SIEM Overview Page : Modify Security Settings Kibana](https://discuss.elastic.co/t/siem-overview-page-modify-security-settings-kibana/244372)

<div class="topic-metadata">

**Author:** [@Saurabh\_Singh1](https://discuss.elastic.co/u/Saurabh_Singh1)\
**Replies:** 4\
**Last updated:** [August 10, 2020, 7:53pm UTC](https://discuss.elastic.co/t/siem-overview-page-modify-security-settings-kibana/244372 "2020-08-10T19:53:12Z")

</div>

Hi I have created two spaces in Kibana : a.) Default b.) Saurabh In saurabh space , i tried to open SIEM overview page , it opened properly. Now we have a link here to modify(enable/disable) security settings in kibana…

---

## [Prebuilt siem rules for cisco IOS and fortigate](https://discuss.elastic.co/t/prebuilt-siem-rules-for-cisco-ios-and-fortigate/244289)

<div class="topic-metadata">

**Author:** [@emahdij](https://discuss.elastic.co/u/emahdij)\
**Replies:** 1\
**Last updated:** [August 10, 2020, 3:36pm UTC](https://discuss.elastic.co/t/prebuilt-siem-rules-for-cisco-ios-and-fortigate/244289 "2020-08-10T15:36:25Z")

</div>

Hi I'm using ELK 7.6 with siem and we have cisco switches and fortigate firewall. Is there prebuilt siem rules for cisco IOS and fortigate?

---

## [Different roles on different fields on different documents](https://discuss.elastic.co/t/different-roles-on-different-fields-on-different-documents/244367)

<div class="topic-metadata">

**Author:** [@luj\_ogluszacz](https://discuss.elastic.co/u/luj_ogluszacz)\
**Replies:** 1\
**Last updated:** [August 10, 2020, 2:49pm UTC](https://discuss.elastic.co/t/different-roles-on-different-fields-on-different-documents/244367 "2020-08-10T14:49:44Z")

</div>

Hi everyone, I have a question. I get a JSON like this { "took" : 271, "timed\_out" : false, "\_shards" : { "total" : 1, "successful" : 1, "skipped" : 0, "failed" : 0 }, "hits" : { "total" : { "value" : 4, "r…

---

## [Unable to run endpoint-security through Elastic Agent](https://discuss.elastic.co/t/unable-to-run-endpoint-security-through-elastic-agent/243631)

<div class="topic-metadata">

**Author:** [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Replies:** 11\
**Last updated:** [August 7, 2020, 6:50pm UTC](https://discuss.elastic.co/t/unable-to-run-endpoint-security-through-elastic-agent/243631 "2020-08-07T18:50:28Z")

</div>

Using the endpoint-security-7.9.0-SNAPSHOT based on commit hash e221c95cd0b0e72d5d153fac57e86feec12db408. OS: Windows 10 Enterprise Version: 2004 Build: 19041.388 Kernel: 10.0.19041.388 (WinBuild.160101.0800) Error …

---

## [Elastic SIEM Map Not Showing Destinations](https://discuss.elastic.co/t/elastic-siem-map-not-showing-destinations/243436)

<div class="topic-metadata">

**Author:** [@Man715](https://discuss.elastic.co/u/Man715)\
**Replies:** 7\
**Last updated:** [August 5, 2020, 8:48pm UTC](https://discuss.elastic.co/t/elastic-siem-map-not-showing-destinations/243436 "2020-08-05T20:48:48Z")

</div>

I have not been able to find any information about this issue. Also, I am very new to the elastic stack. When I look at the SIEM map, it shows some of the destination icons and information but a large amount of destinat…

---

## [Update detection rules from elastic github repository to on-premises](https://discuss.elastic.co/t/update-detection-rules-from-elastic-github-repository-to-on-premises/242211)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 2\
**Last updated:** [August 4, 2020, 4:19pm UTC](https://discuss.elastic.co/t/update-detection-rules-from-elastic-github-repository-to-on-premises/242211 "2020-08-04T16:19:19Z")

</div>

Hi there, I would like to know if is possible to update existing rules from elastic detection rules repository to kibana on-premises? For example: CVE-2020-1350 which has been released by the elastic security team. Th…

---

## [Can I change the primary key for identifying hosts in the SIEM app?](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372)

<div class="topic-metadata">

**Author:** [@macg](https://discuss.elastic.co/u/macg)\
**Replies:** 3\
**Last updated:** [August 4, 2020, 12:12pm UTC](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372 "2020-08-04T12:12:51Z")

</div>

I'm shipping logs from a number of hosts via a single filebeat running on a collector. As a result, the default primary key used by the SIEM app host.name is not very useful to me. host.hostname would work a lot better. …

---

## [SIEM detection signals not showing up](https://discuss.elastic.co/t/siem-detection-signals-not-showing-up/241700)

<div class="topic-metadata">

**Author:** [@Darren\_G](https://discuss.elastic.co/u/Darren_G)\
**Replies:** 8\
**Last updated:** [August 3, 2020, 4:00pm UTC](https://discuss.elastic.co/t/siem-detection-signals-not-showing-up/241700 "2020-08-03T16:00:02Z")

</div>

I am trying to run detections in 7.8 on historical data by changing the time stamps to be recent and reindexing. The data is ECS compliant. The index is in the siem defaultIndex. I have the Additional look-back time set …

---

## [Kibana SIEM Function: Failed to Parse Date field? (Epoch Time)](https://discuss.elastic.co/t/kibana-siem-function-failed-to-parse-date-field-epoch-time/242710)

<div class="topic-metadata">

**Author:** [@cleared\_blue\_sky](https://discuss.elastic.co/u/cleared_blue_sky)\
**Replies:** 8\
**Last updated:** [July 28, 2020, 7:36pm UTC](https://discuss.elastic.co/t/kibana-siem-function-failed-to-parse-date-field-epoch-time/242710 "2020-07-28T19:36:40Z")

</div>

Hi All, Really need some help here. I am trying to use the Kibana SIEM Function; in particular the network function. I have mapped all my fields to ECS standard but for some reason it is returning 'Data Fetch Failure' …

---

## [SIEM signals can not be closed with another status or comment except "Closed"](https://discuss.elastic.co/t/siem-signals-can-not-be-closed-with-another-status-or-comment-except-closed/242755)

<div class="topic-metadata">

**Author:** [@Jan\_Kabelka](https://discuss.elastic.co/u/Jan_Kabelka)\
**Replies:** 1\
**Last updated:** [July 27, 2020, 10:24pm UTC](https://discuss.elastic.co/t/siem-signals-can-not-be-closed-with-another-status-or-comment-except-closed/242755 "2020-07-27T22:24:39Z")

</div>

Dear Elastic Team, we have started to work with your SIEM module. We have defined many detection rules. Signals generated based on these rules can be simply closed (signal.status: "Closed"). We would -of course - like t…

---

## [Yet Another Elastic SIEM Not Showing Hosts](https://discuss.elastic.co/t/yet-another-elastic-siem-not-showing-hosts/241332)

<div class="topic-metadata">

**Author:** [@brian\_m](https://discuss.elastic.co/u/brian_m)\
**Replies:** 10\
**Last updated:** [July 23, 2020, 6:19pm UTC](https://discuss.elastic.co/t/yet-another-elastic-siem-not-showing-hosts/241332 "2020-07-23T18:19:16Z")

</div>

I started playing with Elastic a few months ago, and very recently started trying to get Elastic SIEM to work. I have not been able to get it to recognize anything, and the only host showing up is the Elastic node itself…

---

## [Feature Request: trigger suppresion on signal actions](https://discuss.elastic.co/t/feature-request-trigger-suppresion-on-signal-actions/242335)

<div class="topic-metadata">

**Author:** [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Replies:** 2\
**Last updated:** [July 23, 2020, 3:29pm UTC](https://discuss.elastic.co/t/feature-request-trigger-suppresion-on-signal-actions/242335 "2020-07-23T15:29:42Z")

</div>

Hi, Are we able to get a feature so that when a signal rul runs it only triggers the rule Actions if it has seen X hits in the last Y minuets. Is very helpfull for weeding out false posatives and I am having to do it ex…

---

## [Customize Columns for SIEM Signals and External Alerts not persistent?](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [July 23, 2020, 3:25pm UTC](https://discuss.elastic.co/t/customize-columns-for-siem-signals-and-external-alerts-not-persistent/229825 "2020-07-23T15:25:18Z")

</div>

Hello, Is there a way to make changes to columns for Signals and External Alerts consistent? Because currently by default (7.6.1) External Alerts colums are always reverted to this: Which makes no sense.. As: event.…

---

## [Alerting and customizing SIEM app](https://discuss.elastic.co/t/alerting-and-customizing-siem-app/230207)

<div class="topic-metadata">

**Author:** [@gar](https://discuss.elastic.co/u/gar)\
**Replies:** 11\
**Last updated:** [July 23, 2020, 3:25pm UTC](https://discuss.elastic.co/t/alerting-and-customizing-siem-app/230207 "2020-07-23T15:25:09Z")

</div>

Hi SIEM admins, a couple quick questions. Are there any pans to add alerting to the SIEM app? Specifically the ability to create a watch as part of the Detection Rule setup? I see others have requested allowing custom …

---

## [SIEM xpack subscription](https://discuss.elastic.co/t/siem-xpack-subscription/242114)

<div class="topic-metadata">

**Author:** [@money1968](https://discuss.elastic.co/u/money1968)\
**Replies:** 2\
**Last updated:** [July 22, 2020, 12:00am UTC](https://discuss.elastic.co/t/siem-xpack-subscription/242114 "2020-07-22T00:00:05Z")

</div>

Hey All! Is 'Detections' one of the free pieces with xpack or does it require a license? Thanks!

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=16)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=18)
