# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=18

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 19

---

## [On-prem Deployment Question](https://discuss.elastic.co/t/on-prem-deployment-question/241552)

<div class="topic-metadata">

**Author:** [@jasonwomack](https://discuss.elastic.co/u/jasonwomack)\
**Replies:** 2\
**Last updated:** [July 17, 2020, 4:17pm UTC](https://discuss.elastic.co/t/on-prem-deployment-question/241552 "2020-07-17T16:17:28Z")

</div>

Can someone help me understand when it would be necessary or appropriate to include Logstash in a SIEM deployment? The Getting Started information suggests it's not a default component of a SIEM deployment and it may jus…

---

## [NetFlow Traffic from ASA](https://discuss.elastic.co/t/netflow-traffic-from-asa/239680)

<div class="topic-metadata">

**Author:** [@bushman4](https://discuss.elastic.co/u/bushman4)\
**Replies:** 1\
**Last updated:** [July 16, 2020, 3:22pm UTC](https://discuss.elastic.co/t/netflow-traffic-from-asa/239680 "2020-07-16T15:22:59Z")

</div>

I am a new user of all of this, and I believe I have it set up correctly, but I am seeing some strange results. I have the latest version of filebeat installed, and have the cisco and netflow modules enabled. I have th…

---

## [ELK siem and audit log source options](https://discuss.elastic.co/t/elk-siem-and-audit-log-source-options/240973)

<div class="topic-metadata">

**Author:** [@Altug\_Bozkurt](https://discuss.elastic.co/u/Altug_Bozkurt)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 10:32pm UTC](https://discuss.elastic.co/t/elk-siem-and-audit-log-source-options/240973 "2020-07-15T22:32:21Z")

</div>

Hi everyone, I am considering to try out ELK siem with audit logs but it appears the source of the audit logs has to be through auditbeat daemon provided by ELK, but i have my own daemon with additional functionalities …

---

## [Where does the SIEM saved objects reside?](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 3\
**Last updated:** [July 15, 2020, 10:09pm UTC](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330 "2020-07-15T22:09:45Z")

</div>

hi I was looking into to find Which all index-patterns SIEM app looks by default? How to modify this to include more indices? Where are the saved-objects reside? I was trying to find the objects as per the example doc,…

---

## [Populating SIEM](https://discuss.elastic.co/t/populating-siem/241235)

<div class="topic-metadata">

**Author:** [@darkbeatz](https://discuss.elastic.co/u/darkbeatz)\
**Replies:** 1\
**Last updated:** [July 15, 2020, 9:11am UTC](https://discuss.elastic.co/t/populating-siem/241235 "2020-07-15T09:11:06Z")

</div>

I am reletively new to Elastic SIEM. I have dont some formal training with elastic (2 day entry course) along with the online SIEM fundamentals course. I am also a certifice GIAC GCDA. Our operations team have primarily …

---

## [SIEM Events/All Events Tables Empty](https://discuss.elastic.co/t/siem-events-all-events-tables-empty/240845)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 1\
**Last updated:** [July 13, 2020, 11:31am UTC](https://discuss.elastic.co/t/siem-events-all-events-tables-empty/240845 "2020-07-13T11:31:40Z")

</div>

Finished setting up all the ELK and all looks fine until heading to SIEM page. For some reason the events table in SIEM is looking for fields that does not exist. Can someone point me to the right direction to fix that? …

---

## [Another Feature Request for SIEM](https://discuss.elastic.co/t/another-feature-request-for-siem/239601)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 5\
**Last updated:** [July 8, 2020, 2:23pm UTC](https://discuss.elastic.co/t/another-feature-request-for-siem/239601 "2020-07-08T14:23:14Z")

</div>

Hi, I was thinking that our SIEM really need a feature to query from a file, like in my use case, i have a list of infected domain that i need to query every 15m, the problems is that typing them by hand into the query …

---

## [Include custom Elasticsearch index in SIEM default dashboards](https://discuss.elastic.co/t/include-custom-elasticsearch-index-in-siem-default-dashboards/238878)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 14\
**Last updated:** [July 7, 2020, 3:33pm UTC](https://discuss.elastic.co/t/include-custom-elasticsearch-index-in-siem-default-dashboards/238878 "2020-07-07T15:33:00Z")

</div>

Hi people. I have an ELK server 7.8.0 running OK in testing mode. I've configured Logstash to listen on UDP/514 for incoming syslog remote events, Logstash doesn't apply ani filter, just pass the input to Elasticsearch.…

---

## [SIEM detections](https://discuss.elastic.co/t/siem-detections/240121)

<div class="topic-metadata">

**Author:** [@amalchandran](https://discuss.elastic.co/u/amalchandran)\
**Replies:** 2\
**Last updated:** [July 7, 2020, 1:06pm UTC](https://discuss.elastic.co/t/siem-detections/240121 "2020-07-07T13:06:48Z")

</div>

Hi All I have been trying out SIEM functionalities in ELK 7.8.I have a use case I need to detect and alert 'No logs received for last 6 hours' from a particular host Is it possible using SIEM detection?

---

## [SSH (Secure Shell) to the Internet "rule discrepancy?"](https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094)

<div class="topic-metadata">

**Author:** [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Replies:** 2\
**Last updated:** [July 6, 2020, 11:34am UTC](https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094 "2020-07-06T11:34:39Z")

</div>

Hi, I am looking to get Cisco FNF (Flexible Netflow) and elastic netflow to play nice with me. I don't know if I should report this as a "bug"? When using FNF and get direction on internal flows it feels like the sign…

---

## [DNS Check Malware](https://discuss.elastic.co/t/dns-check-malware/238019)

<div class="topic-metadata">

**Author:** [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Replies:** 8\
**Last updated:** [July 6, 2020, 6:12am UTC](https://discuss.elastic.co/t/dns-check-malware/238019 "2020-07-06T06:12:46Z")

</div>

hi all, how to separate package dns request malware and bitcoin polling in SIEM ?

---

## [Feature request?](https://discuss.elastic.co/t/feature-request/239394)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [July 1, 2020, 3:42am UTC](https://discuss.elastic.co/t/feature-request/239394 "2020-07-01T03:42:27Z")

</div>

Hey, I notices that our siem app has alot of missing features, like the counting query, can we have that like query something then if it pass a threashold then create a detection signal. Since only having able to query …

---

## [SIEM error new install](https://discuss.elastic.co/t/siem-error-new-install/239387)

<div class="topic-metadata">

**Author:** [@jclemons7](https://discuss.elastic.co/u/jclemons7)\
**Replies:** 1\
**Last updated:** [July 1, 2020, 3:33am UTC](https://discuss.elastic.co/t/siem-error-new-install/239387 "2020-07-01T03:33:09Z")

</div>

Hello, I have a filebeat from one ubuntu 20.04 and netflow going to my stack directly into elasticsearch. The stack is one server and it's running native (not in docker or anything) running 7.8. Whenever I try to open…

---

## [Hosts duplicated with and without fqdn](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546)

<div class="topic-metadata">

**Author:** [@Christian\_SANCHEZ](https://discuss.elastic.co/u/Christian_SANCHEZ)\
**Replies:** 6\
**Last updated:** [June 30, 2020, 12:28pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546 "2020-06-30T12:28:47Z")

</div>

Hi I have 7.8 beats installed on Windows servers (audit, metric, file and winlog). They all push events directly to ES In the SIEM, i see my hosts duplicated : once with simple name, once with fqdn It seems winlogbea…

---

## [Cases - Disable external systems prompt](https://discuss.elastic.co/t/cases-disable-external-systems-prompt/239197)

<div class="topic-metadata">

**Author:** [@tacomaster](https://discuss.elastic.co/u/tacomaster)\
**Replies:** 1\
**Last updated:** [June 30, 2020, 1:59am UTC](https://discuss.elastic.co/t/cases-disable-external-systems-prompt/239197 "2020-06-30T01:59:21Z")

</div>

Is there a way to permanently disable the "To send cases to external systems, you need to" prompt that asks to "Upgrade to Elastic Platinum"/"Configure external connector". Right now if I dismiss it, the same prompt come…

---

## [How to configure detection SIEM](https://discuss.elastic.co/t/how-to-configure-detection-siem/238385)

<div class="topic-metadata">

**Author:** [@syafeera](https://discuss.elastic.co/u/syafeera)\
**Replies:** 3\
**Last updated:** [June 29, 2020, 12:43pm UTC](https://discuss.elastic.co/t/how-to-configure-detection-siem/238385 "2020-06-29T12:43:31Z")

</div>

Hi, Problem: data from filebeat appear in SIEM, but at detection the it just empty and show this notification "Let’s set up your detection engine To use the detection engine, a user with the required cluster and index…

---

## [SIEM Timeline through API](https://discuss.elastic.co/t/siem-timeline-through-api/238907)

<div class="topic-metadata">

**Author:** [@forkhead](https://discuss.elastic.co/u/forkhead)\
**Replies:** 1\
**Last updated:** [June 26, 2020, 11:00pm UTC](https://discuss.elastic.co/t/siem-timeline-through-api/238907 "2020-06-26T23:00:38Z")

</div>

Hi, I wanted to know if it is possible to create/update SIEM Timelines through APIs. I am trying to run some correlation logic and save the results of it in a Timeline for further analysis and eventually make it to a cas…

---

## [Send Linux/Windows/NetworkDevices logs to Elastic SIEM](https://discuss.elastic.co/t/send-linux-windows-networkdevices-logs-to-elastic-siem/238903)

<div class="topic-metadata">

**Author:** [@jelocabral](https://discuss.elastic.co/u/jelocabral)\
**Replies:** 1\
**Last updated:** [June 26, 2020, 10:40pm UTC](https://discuss.elastic.co/t/send-linux-windows-networkdevices-logs-to-elastic-siem/238903 "2020-06-26T22:40:06Z")

</div>

Dear people, I have an ELK server 7.8.0. I'm using the SIEM in order to see and monitor netflow and beats data. But now I want to add every syslog messages from Linux, Windows and Network Devices (Cisco and much more).…

---

## ["Machine learning permission error" for demo user](https://discuss.elastic.co/t/machine-learning-permission-error-for-demo-user/238713)

<div class="topic-metadata">

**Author:** [@madduck](https://discuss.elastic.co/u/madduck)\
**Replies:** 1\
**Last updated:** [June 25, 2020, 4:11pm UTC](https://discuss.elastic.co/t/machine-learning-permission-error-for-demo-user/238713 "2020-06-25T16:11:59Z")

</div>

Hi there, I'm trying to create a user with access to the SIEM application as well as the machine learning detections. However I am incapable of coming up with a privilege combination that would allow this. So far the o…

---

## [Tagging Signals with some metadata or tags](https://discuss.elastic.co/t/tagging-signals-with-some-metadata-or-tags/238350)

<div class="topic-metadata">

**Author:** [@forkhead](https://discuss.elastic.co/u/forkhead)\
**Replies:** 2\
**Last updated:** [June 24, 2020, 3:38pm UTC](https://discuss.elastic.co/t/tagging-signals-with-some-metadata-or-tags/238350 "2020-06-24T15:38:01Z")

</div>

Hi, I wanted to know is it possible to tag signals with some keywords like False Positive / True positive / True Positive - not malicious, etc or would it require actually updating the document. I would be interested in …

---

## [Creating cases from signals](https://discuss.elastic.co/t/creating-cases-from-signals/238315)

<div class="topic-metadata">

**Author:** [@forkhead](https://discuss.elastic.co/u/forkhead)\
**Replies:** 2\
**Last updated:** [June 23, 2020, 9:43pm UTC](https://discuss.elastic.co/t/creating-cases-from-signals/238315 "2020-06-23T21:43:48Z")

</div>

Hi, I am trying to understand a couple of things with Detections and Cases in Elastic SIEM - Is there a way to automatically create cases for some rule detections ? Is there a way to store or create Case Templates in C…

---

## [Detection engine scheduler stuck after upgrade](https://discuss.elastic.co/t/detection-engine-scheduler-stuck-after-upgrade/238034)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 5\
**Last updated:** [June 23, 2020, 5:48pm UTC](https://discuss.elastic.co/t/detection-engine-scheduler-stuck-after-upgrade/238034 "2020-06-23T17:48:56Z")

</div>

Hello, I have encountered an issue where after the detection engine rule scheduling, got stuck after upgrade from 7.7.1 to 7.8. I have a setup with two Kibana nodes and there were no other issues during the upgrade, but…

---

## [Adding user.name as a pivot item](https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863)

<div class="topic-metadata">

**Author:** [@forkhead](https://discuss.elastic.co/u/forkhead)\
**Replies:** 2\
**Last updated:** [June 23, 2020, 5:00pm UTC](https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863 "2020-06-23T17:00:07Z")

</div>

Hi, I am playing around with SIEM app and was wondering if there is a way to pivot off of user.name rather than Hosts and IP. I understand I can use Events and filter for both user.name and host.name but might be helpful…

---

## [Aggregation support in SIEM](https://discuss.elastic.co/t/aggregation-support-in-siem/237974)

<div class="topic-metadata">

**Author:** [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Replies:** 2\
**Last updated:** [June 23, 2020, 12:59pm UTC](https://discuss.elastic.co/t/aggregation-support-in-siem/237974 "2020-06-23T12:59:40Z")

</div>

Hi Team, Are there any plans to add an aggregations support in the SIEM app? Maybe the ability to create a correlation rule by leveraging the Elasticsearch aggregations? For example, a very simple use case, where you w…

---

## [Filebeat Events are shown at Kibana Discovery, but not at SIEM](https://discuss.elastic.co/t/filebeat-events-are-shown-at-kibana-discovery-but-not-at-siem/237750)

<div class="topic-metadata">

**Author:** [@Alvaro\_Sanz](https://discuss.elastic.co/u/Alvaro_Sanz)\
**Replies:** 2\
**Last updated:** [June 23, 2020, 6:05am UTC](https://discuss.elastic.co/t/filebeat-events-are-shown-at-kibana-discovery-but-not-at-siem/237750 "2020-06-23T06:05:00Z")

</div>

Hello, When I go to Kibana, I can see my filebeat events at Discovery tab. Nevertheless, if I go to SIEM \> Timeline, I cannot see any of those events. Anyone has any idea why is it happening? Thank you in advance.

---

## [javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/237674)

<div class="topic-metadata">

**Author:** [@Alvaro\_Sanz](https://discuss.elastic.co/u/Alvaro_Sanz)\
**Replies:** 1\
**Last updated:** [June 23, 2020, 3:34am UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/237674 "2020-06-23T03:34:33Z")

</div>

Hello, Since I have enabled and made the configuration for x-pack security, the following message keeps appearing at my elasticsearch log: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate at …

---

## [Palo Alto \[SIEM\]](https://discuss.elastic.co/t/palo-alto-siem/237667)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 2\
**Last updated:** [June 19, 2020, 2:27pm UTC](https://discuss.elastic.co/t/palo-alto-siem/237667 "2020-06-19T14:27:47Z")

</div>

Hi, everyone I have tested with Palo Alto module (Filebeat 7.5.2). I have used this module with Syslog and File inputs. Syslog - module: panw panos: enabled: true var.syslog\_host: 0.0.0.0 var.syslog\_port…

---

## [SIEM can't detect DNS activity to Internet](https://discuss.elastic.co/t/siem-cant-detect-dns-activity-to-internet/236552)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 20\
**Last updated:** [June 17, 2020, 6:44pm UTC](https://discuss.elastic.co/t/siem-cant-detect-dns-activity-to-internet/236552 "2020-06-17T18:44:44Z")

</div>

Dear, I have running an ELK server 7.7 with Elastic SIEM. I have enabled the related pre-built nmap and tcpdump signals detection rules and I could detect these type of "attacks". But now I have enabled the "DNS Activi…

---

## [Simulation of Adobe Hijack](https://discuss.elastic.co/t/simulation-of-adobe-hijack/237281)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 1\
**Last updated:** [June 16, 2020, 3:25pm UTC](https://discuss.elastic.co/t/simulation-of-adobe-hijack/237281 "2020-06-16T15:25:52Z")

</div>

Hi guys, Anyone know how i can simulate this on my personal laptop in order to check the alert? https://www.elastic.co/guide/en/siem/guide/current/adobe-hijack-persistence.html#adobe-hijack-persistence Thanks in advan…

---

## ["SMTP to Internet" signal detection rule is not fired up by Elastic SIEM](https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754)

<div class="topic-metadata">

**Author:** [@jelocabral](https://discuss.elastic.co/u/jelocabral)\
**Replies:** 2\
**Last updated:** [June 16, 2020, 1:35pm UTC](https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754 "2020-06-16T13:35:04Z")

</div>

Hi people, I'm new at this forum so nice to meet you. I'm testing the detection power of Elastic SIEM and in some cases it doesn't detect the rule events. This is a case: Signal detection rule: SMTP to Internet (it's a…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=17)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=19)
