# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=2

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 3

---

## [Cannot view alerted log in security alert](https://discuss.elastic.co/t/cannot-view-alerted-log-in-security-alert/368594)

<div class="topic-metadata">

**Author:** [@Tee55](https://discuss.elastic.co/u/Tee55)\
**Replies:** 4\
**Last updated:** [October 22, 2024, 10:23pm UTC](https://discuss.elastic.co/t/cannot-view-alerted-log-in-security-alert/368594 "2024-10-22T22:23:00Z")

</div>

I tried to create a custom detection rule for MITRE ATT&CK T1078 using the json logs as shown in image below: I upload my log file using " Upload data from a file" integration. Then, I tried to create simple rule us…

---

## [Detection Rules Integration Dependencies](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822)

<div class="topic-metadata">

**Author:** [@syk](https://discuss.elastic.co/u/syk)\
**Replies:** 4\
**Last updated:** [October 16, 2024, 12:49pm UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822 "2024-10-16T12:49:37Z")

</div>

Hi, We experience some issues with detection rules detecting their dependencies on installed integrations correctly: a) Installed Integrations are displayed as "Disabled" complaining there would be no agent policies us…

---

## [The suricata results shown on the \[filebeat dashboard\] are different from the results shown in the \[security -\> alerts\] on kibana](https://discuss.elastic.co/t/the-suricata-results-shown-on-the-filebeat-dashboard-are-different-from-the-results-shown-in-the-security-alerts-on-kibana/366226)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [October 1, 2024, 2:40pm UTC](https://discuss.elastic.co/t/the-suricata-results-shown-on-the-filebeat-dashboard-are-different-from-the-results-shown-in-the-security-alerts-on-kibana/366226 "2024-10-01T14:40:51Z")

</div>

I am using suricata module for the IDS and I am also activating suricata Integrations on SIEM. The filebeat suricata dashboard was created in kibana, and the suricata alert dashboard can also be checked in kibana(Securi…

---

## [How to import suricate.rules into SIEM deteciton rules?](https://discuss.elastic.co/t/how-to-import-suricate-rules-into-siem-deteciton-rules/367093)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [October 1, 2024, 1:51pm UTC](https://discuss.elastic.co/t/how-to-import-suricate-rules-into-siem-deteciton-rules/367093 "2024-10-01T13:51:49Z")

</div>

Hello. I'm using both filebeat suricata module and SIEM suricata agent on kibana. I realized that the results of detection alert are different between filbeat suricata module and SIEM suricata because they use differen…

---

## [Carbon Black Cloud: CEL alert\_v7 400 bad request](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464)

<div class="topic-metadata">

**Author:** [@syk](https://discuss.elastic.co/u/syk)\
**Replies:** 5\
**Last updated:** [September 27, 2024, 7:50am UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464 "2024-09-27T07:50:18Z")

</div>

The Integration Disclaimer reads, that the Alerts-API (v6) for this integration would be deactivated on July 31, 2024. We should transition to CEL input and the alert\_v7 data stream. So we did & the Agent holding the Int…

---

## [Exceptions matches escaping](https://discuss.elastic.co/t/exceptions-matches-escaping/366374)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 2\
**Last updated:** [September 23, 2024, 11:50am UTC](https://discuss.elastic.co/t/exceptions-matches-escaping/366374 "2024-09-23T11:50:52Z")

</div>

We've encountered this rather annoying problem when writing exceptions the documentation on Add and manage exceptions states following: Some characters must be escaped with a backslash, such as \\\\ for a literal backsla…

---

## [Problem with CrowdStrike](https://discuss.elastic.co/t/problem-with-crowdstrike/365146)

<div class="topic-metadata">

**Author:** [@sbeaudoin](https://discuss.elastic.co/u/sbeaudoin)\
**Replies:** 13\
**Last updated:** [September 17, 2024, 12:40pm UTC](https://discuss.elastic.co/t/problem-with-crowdstrike/365146 "2024-09-17T12:40:44Z")

</div>

Hello everyone, I want to integrate crowdstrike on my siem, the kibana interface. I have already preconfigured the following: Generation id and secret: https://api.eu-1.crowdstrike.com. Integration and preconfigu…

---

## [Fortigate Integrations](https://discuss.elastic.co/t/fortigate-integrations/366211)

<div class="topic-metadata">

**Author:** [@arcsons](https://discuss.elastic.co/u/arcsons)\
**Replies:** 8\
**Last updated:** [September 12, 2024, 6:36pm UTC](https://discuss.elastic.co/t/fortigate-integrations/366211 "2024-09-12T18:36:51Z")

</div>

Hi there, I'm a beginner with Elastic and I'm trying to add the "Fortinet FortiGate Firewall Logs" integration to my Elastic setup. I have configured my firewall to send syslog messages to UDP port 9004 on host 192.168.…

---

## [FIM and Windows Updates Best Practices](https://discuss.elastic.co/t/fim-and-windows-updates-best-practices/366415)

<div class="topic-metadata">

**Author:** [@csmith](https://discuss.elastic.co/u/csmith)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 2:04pm UTC](https://discuss.elastic.co/t/fim-and-windows-updates-best-practices/366415 "2024-09-11T14:04:26Z")

</div>

Hi all, When using the File Integrity Module integration, is there a way to tune out expected behavior from Windows updates? Been having a lot of alerts following regular updates. EDIT: I thought about adding an except…

---

## [Security Case Data for Custom Dashboard](https://discuss.elastic.co/t/security-case-data-for-custom-dashboard/365973)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 1\
**Last updated:** [September 5, 2024, 12:34pm UTC](https://discuss.elastic.co/t/security-case-data-for-custom-dashboard/365973 "2024-09-05T12:34:54Z")

</div>

I want to include information about open/closed cases in a custom KPI dashboard. I'm not seeing which index to pull that information from. Does anyone know how I could locate that?

---

## [List all Rules Exceptions](https://discuss.elastic.co/t/list-all-rules-exceptions/365756)

<div class="topic-metadata">

**Author:** [@aptfinf](https://discuss.elastic.co/u/aptfinf)\
**Replies:** 3\
**Last updated:** [August 29, 2024, 4:39pm UTC](https://discuss.elastic.co/t/list-all-rules-exceptions/365756 "2024-08-29T16:39:03Z")

</div>

Hello to everyone. I'm exploring Elastic Defend in a self-hosted cluster with Basic license. I have a question: if i add a Rule Exception (without using Shared Exceptions Lists), is there a way to list all exceptions c…

---

## [Hunt dashboard](https://discuss.elastic.co/t/hunt-dashboard/365764)

<div class="topic-metadata">

**Author:** [@feboxa1431](https://discuss.elastic.co/u/feboxa1431)\
**Replies:** 0\
**Last updated:** [August 29, 2024, 11:42am UTC](https://discuss.elastic.co/t/hunt-dashboard/365764 "2024-08-29T11:42:28Z")

</div>

Hello, Could you help me to understand if in Elastic is such option as "HUNT dashboard" in Security Onion? I mean, is in Elastic such opportunity to aggregate alerts on the dashboard and if so, could you help me to do …

---

## [DNS Tunneling job failing to start](https://discuss.elastic.co/t/dns-tunneling-job-failing-to-start/365635)

<div class="topic-metadata">

**Author:** [@csmith](https://discuss.elastic.co/u/csmith)\
**Replies:** 0\
**Last updated:** [August 27, 2024, 4:56pm UTC](https://discuss.elastic.co/t/dns-tunneling-job-failing-to-start/365635 "2024-08-27T16:56:02Z")

</div>

I have a similar issue to this thread (Anomaly detection - Elastic Jobs failing to start). When I try to start the job packetbeat\_dns\_tunneling, I get the error \[datafeed-packetbeat\_dns\_tunneling\] cannot retrieve field …

---

## [Timeline filter always overwriting first value](https://discuss.elastic.co/t/timeline-filter-always-overwriting-first-value/364666)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 1\
**Last updated:** [August 9, 2024, 6:34pm UTC](https://discuss.elastic.co/t/timeline-filter-always-overwriting-first-value/364666 "2024-08-09T18:34:27Z")

</div>

Hi, I'm having this strange problem (possibly a bug) with timelines in Kibana 8.12.2. When I try to add multiple filters in the timeline builder (the ones under KQL query). The second filter always replaces the first on…

---

## [Detection Exception for Lenovo Temp Account Creation](https://discuss.elastic.co/t/detection-exception-for-lenovo-temp-account-creation/364621)

<div class="topic-metadata">

**Author:** [@FlyNavy](https://discuss.elastic.co/u/FlyNavy)\
**Replies:** 0\
**Last updated:** [August 8, 2024, 5:51pm UTC](https://discuss.elastic.co/t/detection-exception-for-lenovo-temp-account-creation/364621 "2024-08-08T17:51:56Z")

</div>

I have a series of 4 events being generated when the Lenovo Update application runs on a Windows computer. Create account lenovo\_tmp\_####$$$$ (eventID 4720) Enable account lenovo\_tmp\_####$$$$ (eventID 4722) Add lenovo\_…

---

## [Timeline template isn't being applied properly over threshold rules](https://discuss.elastic.co/t/timeline-template-isnt-being-applied-properly-over-threshold-rules/364474)

<div class="topic-metadata">

**Author:** [@elk-siem-user](https://discuss.elastic.co/u/elk-siem-user)\
**Replies:** 0\
**Last updated:** [August 6, 2024, 12:58pm UTC](https://discuss.elastic.co/t/timeline-template-isnt-being-applied-properly-over-threshold-rules/364474 "2024-08-06T12:58:49Z")

</div>

Hi community, Am relatively new to Elastic SIEM feature - Timeline and wanted to understand if am missing out anything or its intentionally built that way. We are building a detection based on threshold rule with custo…

---

## [My low priority alerts are not showing in alerts?](https://discuss.elastic.co/t/my-low-priority-alerts-are-not-showing-in-alerts/363291)

<div class="topic-metadata">

**Author:** [@CtrlCloud-Jelle](https://discuss.elastic.co/u/CtrlCloud-Jelle)\
**Replies:** 1\
**Last updated:** [August 5, 2024, 4:02pm UTC](https://discuss.elastic.co/t/my-low-priority-alerts-are-not-showing-in-alerts/363291 "2024-08-05T16:02:28Z")

</div>

So I've set some rules in the Security solution, and in the Alerts dashboard (Detection and Response) it shows me the alert has fired (which was me that did that). Now when I click the 2 open alerts, it shows nothing…

---

## [Unable to source and feed in the correct information in src country](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019)

<div class="topic-metadata">

**Author:** [@SandeshS](https://discuss.elastic.co/u/SandeshS)\
**Replies:** 3\
**Last updated:** [August 4, 2024, 11:05pm UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019 "2024-08-04T23:05:37Z")

</div>

Hi all, How do I get correct country source in all my fortigate logs? Currently all my logins are showing from a random country for VPN.

---

## [Indicator matching rule with MISP intel with too long duration](https://discuss.elastic.co/t/indicator-matching-rule-with-misp-intel-with-too-long-duration/363617)

<div class="topic-metadata">

**Author:** [@hectorGC](https://discuss.elastic.co/u/hectorGC)\
**Replies:** 0\
**Last updated:** [July 23, 2024, 9:20am UTC](https://discuss.elastic.co/t/indicator-matching-rule-with-misp-intel-with-too-long-duration/363617 "2024-07-23T09:20:53Z")

</div>

Hi all, I am testing MISP integration with a indicator match rule. In the past our team suffered a small outage of a node due to a long execution duration fulfilling the java garbage collector. We are trying again to u…

---

## [Threshold security rule](https://discuss.elastic.co/t/threshold-security-rule/362464)

<div class="topic-metadata">

**Author:** [@luizmeireles](https://discuss.elastic.co/u/luizmeireles)\
**Replies:** 8\
**Last updated:** [July 15, 2024, 8:59pm UTC](https://discuss.elastic.co/t/threshold-security-rule/362464 "2024-07-15T20:59:50Z")

</div>

I am trying to create a Threshold rule-based .. if I have 1 or more events with login failure, create an alert, As you can see in the image, in the Rule preview, some alerts were "found", but this rule is not generat…

---

## [Publish data to Elastic SIEM](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685)

<div class="topic-metadata">

**Author:** [@sateeshkumarb](https://discuss.elastic.co/u/sateeshkumarb)\
**Replies:** 2\
**Last updated:** [July 8, 2024, 5:56pm UTC](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685 "2024-07-08T17:56:42Z")

</div>

Hi, I am trying to ingest some custom security event data (for which there is no Elastic integration) into Elastic SIEM. Looking at this chart: it seems only way to do so is via Elastic agent. However I can't install…

---

## [Trigering Alerts for Machine learning Jobs](https://discuss.elastic.co/t/trigering-alerts-for-machine-learning-jobs/361417)

<div class="topic-metadata">

**Author:** [@apa1](https://discuss.elastic.co/u/apa1)\
**Replies:** 2\
**Last updated:** [July 4, 2024, 3:01am UTC](https://discuss.elastic.co/t/trigering-alerts-for-machine-learning-jobs/361417 "2024-07-04T03:01:02Z")

</div>

Hi, I have created a Machine learning "Job" helping me identify anomalies in traffic for endpoints. Some endpoints are triggering a score range of 97, 98, 99 % . The job is started and runs. I have at the same time c…

---

## [Versions of components used in elasticsearch:8.12.2 and 8.12.0](https://discuss.elastic.co/t/versions-of-components-used-in-elasticsearch-8-12-2-and-8-12-0/361695)

<div class="topic-metadata">

**Author:** [@inkumari](https://discuss.elastic.co/u/inkumari)\
**Replies:** 0\
**Last updated:** [June 19, 2024, 5:41am UTC](https://discuss.elastic.co/t/versions-of-components-used-in-elasticsearch-8-12-2-and-8-12-0/361695 "2024-06-19T05:41:40Z")

</div>

Hi. We are using two versions of elasticsearch in our setup in docker : 8.12.2 and 8.12.0. Due to security reasons, we need to know what are the versions of the following components used in both versions- blas giflib g…

---

## [Detecting inital of breach](https://discuss.elastic.co/t/detecting-inital-of-breach/361154)

<div class="topic-metadata">

**Author:** [@CHEETO](https://discuss.elastic.co/u/CHEETO)\
**Replies:** 1\
**Last updated:** [June 11, 2024, 12:31pm UTC](https://discuss.elastic.co/t/detecting-inital-of-breach/361154 "2024-06-11T12:31:40Z")

</div>

Hello, im currently working on a project where i have to find indicators of compromise and report to my supervisor. Im able to pin point when exactly event is happening but dont know how to figure out which IP address ar…

---

## [Alert triage enhancement ideas](https://discuss.elastic.co/t/alert-triage-enhancement-ideas/359602)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [May 21, 2024, 8:52am UTC](https://discuss.elastic.co/t/alert-triage-enhancement-ideas/359602 "2024-05-21T08:52:56Z")

</div>

Hi everyone, We've been using the alert assignment functionality for a few months now, and it has been incredibly helpful. It really helps us keep track of who worked on what alert. However, we've noticed a couple of is…

---

## [Adding alers to cases in bulk](https://discuss.elastic.co/t/adding-alers-to-cases-in-bulk/359524)

<div class="topic-metadata">

**Author:** [@catn0b0t](https://discuss.elastic.co/u/catn0b0t)\
**Replies:** 1\
**Last updated:** [May 15, 2024, 3:20pm UTC](https://discuss.elastic.co/t/adding-alers-to-cases-in-bulk/359524 "2024-05-15T15:20:44Z")

</div>

Hi, I have some rules generating a lot of alerts (authentication alerts for example) and I noticed a small bug (I think) when adding these to a case. When I only select the alerts shown on the current page of the table, …

---

## [Least-Privilege To View All Server Asset Sending Logs](https://discuss.elastic.co/t/least-privilege-to-view-all-server-asset-sending-logs/359107)

<div class="topic-metadata">

**Author:** [@Michael\_O\_Hara](https://discuss.elastic.co/u/Michael_O_Hara)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 9:04pm UTC](https://discuss.elastic.co/t/least-privilege-to-view-all-server-asset-sending-logs/359107 "2024-05-08T21:04:09Z")

</div>

I was recently granted access into ELK but I cannot see any of the servers/assets that I was told were added & sending logs. What is the minimal RBAC I would need to see the servers & view what kind of volume they are …

---

## [Deployment Architecture Scenarios Using ELK for SIEM at Large Scale on-promise](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525)

<div class="topic-metadata">

**Author:** [@NasrJBr](https://discuss.elastic.co/u/NasrJBr)\
**Replies:** 5\
**Last updated:** [May 1, 2024, 3:49pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525 "2024-05-01T15:49:59Z")

</div>

i want to create some scenarios of deployment of ELK for SIEM usage in a large scale. any help/suggestions about this ?

---

## [Share cases between spaces](https://discuss.elastic.co/t/share-cases-between-spaces/357244)

<div class="topic-metadata">

**Author:** [@Jorge\_Luis\_Sanchez\_C](https://discuss.elastic.co/u/Jorge_Luis_Sanchez_C)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 9:15pm UTC](https://discuss.elastic.co/t/share-cases-between-spaces/357244 "2024-04-11T21:15:34Z")

</div>

Hello, in the Security\>Cases module, how can I share a case between different Spaces?

---

## [Machine learning rules : where to apply the high\_non\_zero\_count function](https://discuss.elastic.co/t/machine-learning-rules-where-to-apply-the-high-non-zero-count-function/358428)

<div class="topic-metadata">

**Author:** [@Poukim0m](https://discuss.elastic.co/u/Poukim0m)\
**Replies:** 0\
**Last updated:** [April 29, 2024, 1:18pm UTC](https://discuss.elastic.co/t/machine-learning-rules-where-to-apply-the-high-non-zero-count-function/358428 "2024-04-29T13:18:18Z")

</div>

hello, Do you know how to apply the high\_non\_zero\_count function (and others according to the documentation) during the creation of a new ML job? Kind regards Vivian

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=1)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=3)
