# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=19

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 20

---

## [Considerations about default terms agg for Elastic SIEM Detections histogram](https://discuss.elastic.co/t/considerations-about-default-terms-agg-for-elastic-siem-detections-histogram/237111)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [June 15, 2020, 7:39pm UTC](https://discuss.elastic.co/t/considerations-about-default-terms-agg-for-elastic-siem-detections-histogram/237111 "2020-06-15T19:39:37Z")

</div>

Hello, Starting from 7.7 the detections histogram in SIEM seems to have an issue with the legend. When 2 digit number get cut off... Also, I'm seriously wondering why the default aggregation is on signal.rule.risk\_sc…

---

## [Update prebuilt ML jobs](https://discuss.elastic.co/t/update-prebuilt-ml-jobs/236896)

<div class="topic-metadata">

**Author:** [@Harm](https://discuss.elastic.co/u/Harm)\
**Replies:** 1\
**Last updated:** [June 14, 2020, 4:36am UTC](https://discuss.elastic.co/t/update-prebuilt-ml-jobs/236896 "2020-06-14T04:36:08Z")

</div>

Hi, According to this site, there should be over 100 prebuilt ML rules. However when I'm going to our Elastic Cloud based Stack, Machine Learning, Job Management, then I only see 20 jobs, some of the versions even look …

---

## [Sysmon v.11 and new 'file delete' event without archive](https://discuss.elastic.co/t/sysmon-v-11-and-new-file-delete-event-without-archive/236141)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 3\
**Last updated:** [June 11, 2020, 8:46am UTC](https://discuss.elastic.co/t/sysmon-v-11-and-new-file-delete-event-without-archive/236141 "2020-06-11T08:46:13Z")

</div>

Anyone know if it's possible to configure Windows Sysmon v.11's new 'File Delete' event not to archive a copy of deleted files in the 'ArchiveDirectory' config key directory (as config key has a default value: Sysmon, he…

---

## [Elastic SIEM for MSSP](https://discuss.elastic.co/t/elastic-siem-for-mssp/235866)

<div class="topic-metadata">

**Author:** [@Gilles\_Villeneuve](https://discuss.elastic.co/u/Gilles_Villeneuve)\
**Replies:** 6\
**Last updated:** [June 11, 2020, 1:20am UTC](https://discuss.elastic.co/t/elastic-siem-for-mssp/235866 "2020-06-11T01:20:46Z")

</div>

Hi All, I have been trying to architect how I could use the Elastic SIEM in a MSSP environment where multiple clients would have a collector ( logstash, Filebeat ), and these would forward the logs to my main ELK stack. …

---

## [Auditbeat OSS fails to start](https://discuss.elastic.co/t/auditbeat-oss-fails-to-start/236261)

<div class="topic-metadata">

**Author:** [@Khasim\_Soudagar](https://discuss.elastic.co/u/Khasim_Soudagar)\
**Replies:** 2\
**Last updated:** [June 10, 2020, 4:07pm UTC](https://discuss.elastic.co/t/auditbeat-oss-fails-to-start/236261 "2020-06-10T16:07:56Z")

</div>

Please find the error message below, i have installed auditbeat and ELK stack from OSS repository. But failed to start auditbeat, can anyone please help me on this. \`\[khasim@vm1\] ~\]$ sudo systemctl status -l auditbeat.s…

---

## [Permission to read SIEM signal index](https://discuss.elastic.co/t/permission-to-read-siem-signal-index/236308)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 6\
**Last updated:** [June 10, 2020, 4:02pm UTC](https://discuss.elastic.co/t/permission-to-read-siem-signal-index/236308 "2020-06-10T16:02:55Z")

</div>

Attempting to adjust our read-only role for SIEM viewers, but users fails to get permission to the signal index, wondering how to allow read/search access to this? When Users access the SIEM app thay get this error: \[s…

---

## [FIM module in auditbeat keeps too many file handles open on Kubrenetes](https://discuss.elastic.co/t/fim-module-in-auditbeat-keeps-too-many-file-handles-open-on-kubrenetes/236239)

<div class="topic-metadata">

**Author:** [@premendra2020singh](https://discuss.elastic.co/u/premendra2020singh)\
**Replies:** 2\
**Last updated:** [June 8, 2020, 11:31pm UTC](https://discuss.elastic.co/t/fim-module-in-auditbeat-keeps-too-many-file-handles-open-on-kubrenetes/236239 "2020-06-08T23:31:16Z")

</div>

I'm using Auditbeat with FIM module on Kubernetes daemonset with 40 pods on it. Auditbeat version - latest OS - Debian GNU/Linux 9 ulimit -n 1048576 Auditbeat pod memory allocation - 200mb Open file handles go up …

---

## [Fetching Cisco , Firewall logs from syslog-ng server](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951)

<div class="topic-metadata">

**Author:** [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Replies:** 10\
**Last updated:** [June 8, 2020, 1:18pm UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951 "2020-06-08T13:18:31Z")

</div>

I have a syslog-ng server which gathers data from Cisco Router, switches, netflow data and firewall related data . The data is stored as flat files. Now, i am looking to send those to ELK SIEM . I see that i can use fi…

---

## [Aggregation facility in the detections rules tab?](https://discuss.elastic.co/t/aggregation-facility-in-the-detections-rules-tab/235080)

<div class="topic-metadata">

**Author:** [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Replies:** 1\
**Last updated:** [June 5, 2020, 4:48pm UTC](https://discuss.elastic.co/t/aggregation-facility-in-the-detections-rules-tab/235080 "2020-06-05T16:48:00Z")

</div>

can we write aggregation in the detection rules tab?. if not, is it a planned feature?

---

## [Addition of other visualizations in Elastic-SIEM dashboards](https://discuss.elastic.co/t/addition-of-other-visualizations-in-elastic-siem-dashboards/235078)

<div class="topic-metadata">

**Author:** [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Replies:** 1\
**Last updated:** [June 5, 2020, 4:11pm UTC](https://discuss.elastic.co/t/addition-of-other-visualizations-in-elastic-siem-dashboards/235078 "2020-06-05T16:11:06Z")

</div>

There are pre-built visualizations in the Elastic-SIEM section in Kibana. Can I add additional visualizations that I previously created in the visualizations, to the Elastic-SIEM section?

---

## [Correlation in Elastic-SIEM](https://discuss.elastic.co/t/correlation-in-elastic-siem/235075)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 1\
**Last updated:** [June 4, 2020, 1:54pm UTC](https://discuss.elastic.co/t/correlation-in-elastic-siem/235075 "2020-06-04T13:54:27Z")

</div>

How well we can have a correlation using the Elastic-SIEM application? A sample use case would be I want to know, in the last 15minutes, for the events tagged that were tagged as "attack", whether the source IPs are eq…

---

## [SIEM Alert Actions not updating](https://discuss.elastic.co/t/siem-alert-actions-not-updating/234968)

<div class="topic-metadata">

**Author:** [@Mercwri](https://discuss.elastic.co/u/Mercwri)\
**Replies:** 5\
**Last updated:** [June 2, 2020, 7:40pm UTC](https://discuss.elastic.co/t/siem-alert-actions-not-updating/234968 "2020-06-02T19:40:06Z")

</div>

I've gone through a few iterations of alert actions, checking both the API and the UI the SIEM app shows my current version of the actions, but when an alert is sent it uses a previous version of the actions. I've restar…

---

## [SIEM -- Event Columns (Only Default Category)](https://discuss.elastic.co/t/siem-event-columns-only-default-category/234478)

<div class="topic-metadata">

**Author:** [@clearedskies](https://discuss.elastic.co/u/clearedskies)\
**Replies:** 8\
**Last updated:** [June 1, 2020, 2:15pm UTC](https://discuss.elastic.co/t/siem-event-columns-only-default-category/234478 "2020-06-01T14:15:18Z")

</div>

Hopefully, someone can help: In the SIEM section of Kibana, in the events section, I wish to customise the columns shown (I have parsed these logs using Logstash and wish to use these filters in the plugin). It appears…

---

## [Graylog logs directed to Elastic SIEM](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 5\
**Last updated:** [June 1, 2020, 12:32pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750 "2020-06-01T12:32:14Z")

</div>

Hi people, I have a Graylog server fulfilled of a lot of network and host logs. On the other hand, I have a new Elastic SIEM 7.7 implementation and some servers with different beats that point to it. But I have to dire…

---

## [Kibana SIEM app performance](https://discuss.elastic.co/t/kibana-siem-app-performance/234358)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 10\
**Last updated:** [May 29, 2020, 11:01am UTC](https://discuss.elastic.co/t/kibana-siem-app-performance/234358 "2020-05-29T11:01:43Z")

</div>

Hello, we are experiencing some performance issues in Kibana SIEM app especially loading the Detections tab. Making it very annoying to use. The queries report times ~8ms (Signal count) ~33ms (Inspect signals). But the…

---

## [Create custom rule to monitor the logins only in day time?](https://discuss.elastic.co/t/create-custom-rule-to-monitor-the-logins-only-in-day-time/229743)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 2\
**Last updated:** [April 28, 2020, 3:44am UTC](https://discuss.elastic.co/t/create-custom-rule-to-monitor-the-logins-only-in-day-time/229743 "2020-04-28T03:44:12Z")

</div>

Hey Guys, I am creating my custom rule to monitor the filebeat-\* events to monitor login events only between 09:00 to 20:00. And needs to send an alert if any event happens after the said period. Can we do that with cus…

---

## [Cisco Umbrella Ingest](https://discuss.elastic.co/t/cisco-umbrella-ingest/234068)

<div class="topic-metadata">

**Author:** [@jasonmull](https://discuss.elastic.co/u/jasonmull)\
**Replies:** 1\
**Last updated:** [May 25, 2020, 9:23am UTC](https://discuss.elastic.co/t/cisco-umbrella-ingest/234068 "2020-05-25T09:23:57Z")

</div>

Hello, I'm trying to integrate multi-tenant Cisco Umbrella DNS logs into Elastic SIEM and I'm running into a few issues. These logs are located in an AWS S3 bucket. Individual log files are generated as csv and gzippe…

---

## [Alerting by amount of "hits"](https://discuss.elastic.co/t/alerting-by-amount-of-hits/233715)

<div class="topic-metadata">

**Author:** [@Or\_Biran](https://discuss.elastic.co/u/Or_Biran)\
**Replies:** 1\
**Last updated:** [May 21, 2020, 12:11pm UTC](https://discuss.elastic.co/t/alerting-by-amount-of-hits/233715 "2020-05-21T12:11:52Z")

</div>

Hi, I want to create a detection rule that if was X unauthorized events then Alert\\Create a signal... how can I do that? thanks!

---

## [Event correlation in 7.7](https://discuss.elastic.co/t/event-correlation-in-7-7/233621)

<div class="topic-metadata">

**Author:** [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Replies:** 1\
**Last updated:** [May 21, 2020, 12:02pm UTC](https://discuss.elastic.co/t/event-correlation-in-7-7/233621 "2020-05-21T12:02:50Z")

</div>

Hi all, Following on from the release of 7.7.0 and the new "Alerting and Actions" feature, I'm wondering what the best method of alerting based on correlated events would be. Loking to implement Alerting using the stac…

---

## [SSH auth logs not visualized in Kibana](https://discuss.elastic.co/t/ssh-auth-logs-not-visualized-in-kibana/227484)

<div class="topic-metadata">

**Author:** [@ArnimS](https://discuss.elastic.co/u/ArnimS)\
**Replies:** 5\
**Last updated:** [May 19, 2020, 1:34am UTC](https://discuss.elastic.co/t/ssh-auth-logs-not-visualized-in-kibana/227484 "2020-05-19T01:34:03Z")

</div>

Hi everyone! I'm relatively new to the Elasticstack and currently trying to set up a centralized dashboard for the logs of all my servers. (And also use the system to replicate all logs to my monitoring server, where I'…

---

## [Filebeat Cisco Module: Listening on IPV6 only?](https://discuss.elastic.co/t/filebeat-cisco-module-listening-on-ipv6-only/229716)

<div class="topic-metadata">

**Author:** [@madhatt](https://discuss.elastic.co/u/madhatt)\
**Replies:** 1\
**Last updated:** [May 19, 2020, 1:22am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-listening-on-ipv6-only/229716 "2020-05-19T01:22:47Z")

</div>

I have configured the Cisco module to listen on 0.0.0.0 UDP/514. If I use echo and netcat to send a message from localhost, I can see it come in (on loopback) with tcpdump, and filebeat parses the message successfully. …

---

## [False positive on SIEM rule SSH to the Internet](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [May 18, 2020, 5:10pm UTC](https://discuss.elastic.co/t/false-positive-on-siem-rule-ssh-to-the-internet/233070 "2020-05-18T17:10:41Z")

</div>

Hello, This is the query for the "SSH to the Internet" Rule: network.transport: tcp and destination.port:22 and ( network.direction: outbound or ( source.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) …

---

## [Can Elastic SIEM have a Group By feature in the Timelines?](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725)

<div class="topic-metadata">

**Author:** [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Replies:** 4\
**Last updated:** [May 15, 2020, 10:00pm UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725 "2020-05-15T22:00:47Z")

</div>

Hello, When it comes to Elastic Stack is has great functionalities for specific detection trigerred by well tuned rules but security analysts struggle when it comes to generic checks like if I have a phishing related p…

---

## [Unifi Ubiquity USG IPS Suricata Filebeat Logging](https://discuss.elastic.co/t/unifi-ubiquity-usg-ips-suricata-filebeat-logging/229891)

<div class="topic-metadata">

**Author:** [@Dallas\_Toth](https://discuss.elastic.co/u/Dallas_Toth)\
**Replies:** 2\
**Last updated:** [May 14, 2020, 10:49pm UTC](https://discuss.elastic.co/t/unifi-ubiquity-usg-ips-suricata-filebeat-logging/229891 "2020-05-14T22:49:20Z")

</div>

So with some help from multiple sources. On Elastic 7.6.2 and Unifi Controller 5.12.66 https://redmine.openinfosecfoundation.org/projects/suricata/wiki/\_Logstash\_Kibana\_and\_Suricata\_JSON\_output https://pastebin.co…

---

## [Bytes In / Bytes Out Empty](https://discuss.elastic.co/t/bytes-in-bytes-out-empty/232441)

<div class="topic-metadata">

**Author:** [@insanity13](https://discuss.elastic.co/u/insanity13)\
**Replies:** 1\
**Last updated:** [May 13, 2020, 10:36pm UTC](https://discuss.elastic.co/t/bytes-in-bytes-out-empty/232441 "2020-05-13T22:36:34Z")

</div>

Elastic Cloud with APM via .NET Classic Agent. Goes to the SIEM Source IPs, and see that Bytes In / Bytes Out are Empty AMP transaction contains request and response length. So I think these fields should be filled.

---

## [SIEM Network Page Queries all indexes](https://discuss.elastic.co/t/siem-network-page-queries-all-indexes/231490)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 4\
**Last updated:** [May 13, 2020, 2:31pm UTC](https://discuss.elastic.co/t/siem-network-page-queries-all-indexes/231490 "2020-05-13T14:31:26Z")

</div>

Hi I have recently spent a lot of time getting a few of my data sources ingested in ECS format so that I can get the benefits from the SIEM capability. Some data comes direct from the \*beats tools but some are via Logs…

---

## [Timelines Event Renderer - Why I don't see this in my timeline](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258)

<div class="topic-metadata">

**Author:** [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Replies:** 3\
**Last updated:** [May 6, 2020, 9:14pm UTC](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258 "2020-05-06T21:14:15Z")

</div>

So, I was parsing Fortigate events in a compliant way to ECS with some enrichment by adding categorization fields with logstash but instead of getting this : I get this : Even though I respected categorization fiel…

---

## [False Positive - RPC (Remote Procedure Call) to the Internet (Kuery)](https://discuss.elastic.co/t/false-positive-rpc-remote-procedure-call-to-the-internet-kuery/231178)

<div class="topic-metadata">

**Author:** [@Gary\_Blackwell](https://discuss.elastic.co/u/Gary_Blackwell)\
**Replies:** 2\
**Last updated:** [May 6, 2020, 8:46pm UTC](https://discuss.elastic.co/t/false-positive-rpc-remote-procedure-call-to-the-internet-kuery/231178 "2020-05-06T20:46:47Z")

</div>

There is a built-in detection rule watching for TCP traffic on port 135 to the Internet. network.transport: tcp and destination.port: 135 and (network.direction: outbound or (source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 19…

---

## [Do we have SIEM dashboards and detection anomaly for DHCP logs?](https://discuss.elastic.co/t/do-we-have-siem-dashboards-and-detection-anomaly-for-dhcp-logs/231161)

<div class="topic-metadata">

**Author:** [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Replies:** 3\
**Last updated:** [May 6, 2020, 5:27pm UTC](https://discuss.elastic.co/t/do-we-have-siem-dashboards-and-detection-anomaly-for-dhcp-logs/231161 "2020-05-06T17:27:10Z")

</div>

Hi Team, I have on boarded DHCP logs into ELK and looking for SIEM detection anomaly for DHCP logs. I didn't seen anything dashboard related for DHCP logs in SIEM DHCP logs example :-1 Fields: ID,Date,Time,Descriptio…

---

## [Field case sensitivity and detection rules not triggering 'clear-eventlog'](https://discuss.elastic.co/t/field-case-sensitivity-and-detection-rules-not-triggering-clear-eventlog/230167)

<div class="topic-metadata">

**Author:** [@jimmburton](https://discuss.elastic.co/u/jimmburton)\
**Replies:** 3\
**Last updated:** [April 29, 2020, 2:57pm UTC](https://discuss.elastic.co/t/field-case-sensitivity-and-detection-rules-not-triggering-clear-eventlog/230167 "2020-04-29T14:57:44Z")

</div>

I have an new on-prem deployment of ELK 7.6.2, and have been working the the SIEM tool and like in another post about not seeing a signal get triggered when clearing logs I had the same issue. I worked through the winlog…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=18)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=20)
