# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=20

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 21

---

## [Prebuilt ML Jobs cant be activated](https://discuss.elastic.co/t/prebuilt-ml-jobs-cant-be-activated/229138)

<div class="topic-metadata">

**Author:** [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)\
**Replies:** 10\
**Last updated:** [April 25, 2020, 3:58pm UTC](https://discuss.elastic.co/t/prebuilt-ml-jobs-cant-be-activated/229138 "2020-04-25T15:58:50Z")

</div>

Hello all, I´m trying to activate all prebuilt Machine Learning Jobs, but cant success it. I Try to active them from the SIEM "Anomalies Detection" menu, but mostly jobs don´t get activated. More properly, I could act…

---

## [Signal SIEM Detections using log files](https://discuss.elastic.co/t/signal-siem-detections-using-log-files/226667)

<div class="topic-metadata">

**Author:** [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)\
**Replies:** 4\
**Last updated:** [April 25, 2020, 12:26am UTC](https://discuss.elastic.co/t/signal-siem-detections-using-log-files/226667 "2020-04-25T00:26:44Z")

</div>

Hello, I ingested some data from firewall devices of which I would like to create rules in the Detections part of the Elastic SIEM. I created a rule to detect Malware using a field of the log file which has that inform…

---

## [Lots of unmapped fields in .siem-signals-default](https://discuss.elastic.co/t/lots-of-unmapped-fields-in-siem-signals-default/229594)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [April 24, 2020, 1:56pm UTC](https://discuss.elastic.co/t/lots-of-unmapped-fields-in-siem-signals-default/229594 "2020-04-24T13:56:11Z")

</div>

Hello, There seem to be quite a bit of unmapped fields in .siem-signals-default index. I tried refreshing the index pattern, but the fields are not added. The result is I can't use certain fields: For example a searc…

---

## [SIEM does not show data](https://discuss.elastic.co/t/siem-does-not-show-data/229010)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 7\
**Last updated:** [April 23, 2020, 7:50am UTC](https://discuss.elastic.co/t/siem-does-not-show-data/229010 "2020-04-23T07:50:13Z")

</div>

I got the problem: Fielddata is disabled on text fields by default. Set fielddata=true on \[source.ip\] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant me…

---

## [Kibana SIEM display problem just spinning no error](https://discuss.elastic.co/t/kibana-siem-display-problem-just-spinning-no-error/228488)

<div class="topic-metadata">

**Author:** [@Bartekk](https://discuss.elastic.co/u/Bartekk)\
**Replies:** 7\
**Last updated:** [April 22, 2020, 2:18pm UTC](https://discuss.elastic.co/t/kibana-siem-display-problem-just-spinning-no-error/228488 "2020-04-22T14:18:48Z")

</div>

Hi i've problem in SIEM/NETWORK/Flows i've just spinning ring and nothing displays , before update everything was fine. and log https://pastebin.pl/view/88c362e3 i dont see nothing special here ;/ No idea how to fix …

---

## [Aggregation of incoming events on common fields for SIEM usecase](https://discuss.elastic.co/t/aggregation-of-incoming-events-on-common-fields-for-siem-usecase/229206)

<div class="topic-metadata">

**Author:** [@ParashB](https://discuss.elastic.co/u/ParashB)\
**Replies:** 0\
**Last updated:** [April 22, 2020, 8:26am UTC](https://discuss.elastic.co/t/aggregation-of-incoming-events-on-common-fields-for-siem-usecase/229206 "2020-04-22T08:26:36Z")

</div>

How can I do aggregation of incoming events on common fields to reduce the incoming EPS? Refer the AGGREGATION OF EVENTS section in "https://socprime.com/en/blog/arcsight-optimizing-eps-aggregation-and-filtration/" for m…

---

## [How to apply Third Party or Custom Threat intel feeds with SIEM App?](https://discuss.elastic.co/t/how-to-apply-third-party-or-custom-threat-intel-feeds-with-siem-app/228312)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 2\
**Last updated:** [April 22, 2020, 2:58am UTC](https://discuss.elastic.co/t/how-to-apply-third-party-or-custom-threat-intel-feeds-with-siem-app/228312 "2020-04-22T02:58:32Z")

</div>

Hi Guys, Can anyone please suggest me the way to apply third party threat intel feed to SIEM App? Has that to be done with logstash translate dictionary feature? but since there are multiple indices involved can someone…

---

## [Signal Detection Rules](https://discuss.elastic.co/t/signal-detection-rules/219887)

<div class="topic-metadata">

**Author:** [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Replies:** 11\
**Last updated:** [April 21, 2020, 11:08am UTC](https://discuss.elastic.co/t/signal-detection-rules/219887 "2020-04-21T11:08:23Z")

</div>

These don't seem to be working for me. I have enabled all rules for Linux and Windows. There are two rules based upon the whoami command. One for windows and one for linux. I performed the whoami command on both host…

---

## [Can i write elastic query using KQL or Lucene](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337)

<div class="topic-metadata">

**Author:** [@Saurabh\_Singh1](https://discuss.elastic.co/u/Saurabh_Singh1)\
**Replies:** 2\
**Last updated:** [April 21, 2020, 4:19am UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337 "2020-04-21T04:19:44Z")

</div>

I was trying to replicate watcher functionality using SIEM detection rule. In watcher i can write elastic query, but can i perform that using detection rule ? Please help.

---

## [Prebuilt ML jobs fail](https://discuss.elastic.co/t/prebuilt-ml-jobs-fail/227309)

<div class="topic-metadata">

**Author:** [@kfs](https://discuss.elastic.co/u/kfs)\
**Replies:** 9\
**Last updated:** [April 20, 2020, 1:02pm UTC](https://discuss.elastic.co/t/prebuilt-ml-jobs-fail/227309 "2020-04-20T13:02:44Z")

</div>

Hi, I have an issue with starting prebuilt ML jobs that use winlogbeat\* data. The job logs show that lookback returned no data but actually I am pretty sure that it is as SIEM dashboard shows winlogbeat events coming fr…

---

## [Elastic SIEM does not show the netflow data using filebeat](https://discuss.elastic.co/t/elastic-siem-does-not-show-the-netflow-data-using-filebeat/228771)

<div class="topic-metadata">

**Author:** [@Minh\_Ti\_n\_Tr\_n](https://discuss.elastic.co/u/Minh_Ti_n_Tr_n)\
**Replies:** 0\
**Last updated:** [April 20, 2020, 2:58am UTC](https://discuss.elastic.co/t/elastic-siem-does-not-show-the-netflow-data-using-filebeat/228771 "2020-04-20T02:58:28Z")

</div>

Hi all, I configured filebeat netflow module to receive netflow log from pfsense It shows data received but don't show anything on visualize Any solution to solve that? Please let me know if you need any config f…

---

## [Rules in ElasticSIEM not create signals](https://discuss.elastic.co/t/rules-in-elasticsiem-not-create-signals/228068)

<div class="topic-metadata">

**Author:** [@Nazarenko](https://discuss.elastic.co/u/Nazarenko)\
**Replies:** 4\
**Last updated:** [April 16, 2020, 2:23pm UTC](https://discuss.elastic.co/t/rules-in-elasticsiem-not-create-signals/228068 "2020-04-16T14:23:48Z")

</div>

Hello, i have some problem with rules in ElasticSIEM. I have a lot of indexies but in on of them rules don't working. Messages about error rules are absent. WIth one index rule are working but when i write rule for other…

---

## [ECS common schema taxonomies for other sources](https://discuss.elastic.co/t/ecs-common-schema-taxonomies-for-other-sources/228220)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 1\
**Last updated:** [April 16, 2020, 11:20am UTC](https://discuss.elastic.co/t/ecs-common-schema-taxonomies-for-other-sources/228220 "2020-04-16T11:20:31Z")

</div>

Hi there We are looking at pushing events from a lot of our network and security devices into Elastic for storage, and utilising the SIEM functionality as well. We understand the requirement for ECS, and we have starte…

---

## [SOAR for elk](https://discuss.elastic.co/t/soar-for-elk/228133)

<div class="topic-metadata">

**Author:** [@oumy](https://discuss.elastic.co/u/oumy)\
**Replies:** 2\
**Last updated:** [April 16, 2020, 11:03am UTC](https://discuss.elastic.co/t/soar-for-elk/228133 "2020-04-16T11:03:02Z")

</div>

Hello there, i was wondering if there is an open source SOAR that can be integrated with elk stack, and if so how to do so? and does any of you know how too integrate PatrOwl with elk stack? Thank you

---

## [Sizing Parameters for deploying SIEM](https://discuss.elastic.co/t/sizing-parameters-for-deploying-siem/228240)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 0\
**Last updated:** [April 16, 2020, 4:29am UTC](https://discuss.elastic.co/t/sizing-parameters-for-deploying-siem/228240 "2020-04-16T04:29:18Z")

</div>

Hi Guys, I am planning to test out SIEM app in production and I have around 70-80 servers \[60 of are those Windows/rest are all Linux/Unix\] then have PAN Firewall, 4-5 Cisco routers. So around 90 off devices that needs…

---

## [bulkResponse had errors with response statuses:counts of... {](https://discuss.elastic.co/t/bulkresponse-had-errors-with-response-statuses-counts-of/226492)

<div class="topic-metadata">

**Author:** [@larryzhu](https://discuss.elastic.co/u/larryzhu)\
**Replies:** 5\
**Last updated:** [April 15, 2020, 1:28pm UTC](https://discuss.elastic.co/t/bulkresponse-had-errors-with-response-statuses-counts-of/226492 "2020-04-15T13:28:56Z")

</div>

We consistently hit the invalid request error in elastic SIEM Found 10000 signals from the indexes of "\[oci-audit-span\*\]" using signal rule name: "OCI Audit: Delete VCN \[Duplicate\]", id: "0e2d1191-7600-4268-be75-0f13ce1…

---

## [IP Watch List Functionality](https://discuss.elastic.co/t/ip-watch-list-functionality/223583)

<div class="topic-metadata">

**Author:** [@derricksong](https://discuss.elastic.co/u/derricksong)\
**Replies:** 6\
**Last updated:** [April 15, 2020, 5:04am UTC](https://discuss.elastic.co/t/ip-watch-list-functionality/223583 "2020-04-15T05:04:49Z")

</div>

Hello, Trying to implement an IP Watch List in SIEM and wondering if there was any guidance/best practices in doing so. I currently have an index where new malicious IP objects are logged on a regular basis, let's say …

---

## [Zeek filebeat - HTTP and TLS events not fully populating](https://discuss.elastic.co/t/zeek-filebeat-http-and-tls-events-not-fully-populating/224830)

<div class="topic-metadata">

**Author:** [@lw24](https://discuss.elastic.co/u/lw24)\
**Replies:** 3\
**Last updated:** [April 11, 2020, 11:14am UTC](https://discuss.elastic.co/t/zeek-filebeat-http-and-tls-events-not-fully-populating/224830 "2020-04-11T11:14:10Z")

</div>

I have a Security Onion VM with Filebeats on it with Zeek module enabled. I've edited the zeek.yml file to point to /nsm/bro/logs/current and have all the events being pulled through to Kibana. DNS events are fully popu…

---

## [SIEM doesn't show any Winlogbeat events, despite ES receiving them](https://discuss.elastic.co/t/siem-doesnt-show-any-winlogbeat-events-despite-es-receiving-them/224008)

<div class="topic-metadata">

**Author:** [@Aura](https://discuss.elastic.co/u/Aura)\
**Replies:** 11\
**Last updated:** [April 10, 2020, 8:38pm UTC](https://discuss.elastic.co/t/siem-doesnt-show-any-winlogbeat-events-despite-es-receiving-them/224008 "2020-04-10T20:38:13Z")

</div>

Hi, New ELK stack user here. I just installed v7.6.1 on a Ubuntu Server 18.04 that I have running on an old Lenovo I had lying around. Took me a couple of hours to install, set up, and get working. One issue I can't see…

---

## [Detections will not setup](https://discuss.elastic.co/t/detections-will-not-setup/227297)

<div class="topic-metadata">

**Author:** [@xennn](https://discuss.elastic.co/u/xennn)\
**Replies:** 4\
**Last updated:** [April 10, 2020, 5:41pm UTC](https://discuss.elastic.co/t/detections-will-not-setup/227297 "2020-04-10T17:41:11Z")

</div>

Hello, i have a problem with setup detections in SIEM. I always get a message with Let's set up your detection engine. I have logged in as a superuser i cannot see the .siem-signals index. I have check the role i hav…

---

## [Adding a condition in detection engine](https://discuss.elastic.co/t/adding-a-condition-in-detection-engine/227331)

<div class="topic-metadata">

**Author:** [@Saurabh\_Singh1](https://discuss.elastic.co/u/Saurabh_Singh1)\
**Replies:** 1\
**Last updated:** [April 10, 2020, 1:35pm UTC](https://discuss.elastic.co/t/adding-a-condition-in-detection-engine/227331 "2020-04-10T13:35:24Z")

</div>

Hi Team, Can we write an elastic query in condition while defining Detection Rule. I was generating alert using WATCHERS. IT had input , condition and output. I wanted to replicate this functionality using DETECTION …

---

## [Display log information](https://discuss.elastic.co/t/display-log-information/227380)

<div class="topic-metadata">

**Author:** [@Gary\_Blackwell](https://discuss.elastic.co/u/Gary_Blackwell)\
**Replies:** 0\
**Last updated:** [April 9, 2020, 5:45pm UTC](https://discuss.elastic.co/t/display-log-information/227380 "2020-04-09T17:45:27Z")

</div>

The default display "\_source" has a lot of uninteresting data. So I went to advanced settings and modified the default columns to be "winlog.event\_id, event.action, winlog.event\_data.SubjectUserName, winlog.event\_data.Su…

---

## [Host.hostname field\_data issue with SIEM and auditbeat](https://discuss.elastic.co/t/host-hostname-field-data-issue-with-siem-and-auditbeat/226945)

<div class="topic-metadata">

**Author:** [@rgeisman](https://discuss.elastic.co/u/rgeisman)\
**Replies:** 0\
**Last updated:** [April 7, 2020, 3:56pm UTC](https://discuss.elastic.co/t/host-hostname-field-data-issue-with-siem-and-auditbeat/226945 "2020-04-07T15:56:45Z")

</div>

Hello All, I am setting up an ELK stack and auditbeat and filebeat are sending logs to logstash and ingesting them correctly in Elasticsearch. When I go to SIEM, an error is thrown in the host and network section that …

---

## [How to handle network.direction:unknown?](https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 2\
**Last updated:** [April 4, 2020, 4:29pm UTC](https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143 "2020-04-04T16:29:14Z")

</div>

I'm getting detections where the network.direction is "unknown". Upon investigation this is just the source port from a vulnerability scanner (Detectify) : "destination": { "bytes": 4128, "ip": "52.17.98.131",…

---

## [Shodan Integration](https://discuss.elastic.co/t/shodan-integration/223425)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 4\
**Last updated:** [April 1, 2020, 12:41pm UTC](https://discuss.elastic.co/t/shodan-integration/223425 "2020-04-01T12:41:18Z")

</div>

Has anyone managed to get Shodan.io alerts into Elastic SIEM? I'm trying to use kubi-ecs-logger logging library and the shodan python api to send ECS alerts and wondered if anyone is interested in collaborating? H

---

## [SIEM detections false positive](https://discuss.elastic.co/t/siem-detections-false-positive/219287)

<div class="topic-metadata">

**Author:** [@danielsnelling](https://discuss.elastic.co/u/danielsnelling)\
**Replies:** 4\
**Last updated:** [March 2, 2020, 9:50pm UTC](https://discuss.elastic.co/t/siem-detections-false-positive/219287 "2020-03-02T21:50:37Z")

</div>

We've upgraded our stack to 7.6.0 yesterday, and we love the new Detections mechanism! I'm aware these are in beta, but some of the definitions have a boolean 'or' where there should be an 'and'. This is particularly w…

---

## [7.6.1 SIEM not showing packetbeat flow asn info](https://discuss.elastic.co/t/7-6-1-siem-not-showing-packetbeat-flow-asn-info/225293)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [March 26, 2020, 9:35pm UTC](https://discuss.elastic.co/t/7-6-1-siem-not-showing-packetbeat-flow-asn-info/225293 "2020-03-26T21:35:48Z")

</div>

Hello, I was trying to enrich our flow data a bit from our Packetbeat data. Adding geoip data worked fine and showed up in SIEM, but I have some isues getting ASN info shown correctly in SIEM. So I made this processor: …

---

## [Sum of source bytes seems impossibly large](https://discuss.elastic.co/t/sum-of-source-bytes-seems-impossibly-large/219961)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [March 26, 2020, 10:33am UTC](https://discuss.elastic.co/t/sum-of-source-bytes-seems-impossibly-large/219961 "2020-03-26T10:33:07Z")

</div>

Hello, Was browsing through Kibana SIEM on 7.5.2 and discovered some weird 'Bytes In', 'Bytes Out' metrics. After investigating, it seemd like some servers were sending huge amounts of traffic to my Elastic ingest nodes…

---

## [Logstash Output Dashboards](https://discuss.elastic.co/t/logstash-output-dashboards/224370)

<div class="topic-metadata">

**Author:** [@xennn](https://discuss.elastic.co/u/xennn)\
**Replies:** 0\
**Last updated:** [March 20, 2020, 7:55am UTC](https://discuss.elastic.co/t/logstash-output-dashboards/224370 "2020-03-20T07:55:49Z")

</div>

Hello, is it possible if we use a cluster to use the siem app, if we forward the logs to logstash? If we install winbeat, and configure the logstash output, we dont get the siem app working. The index was renamed to w…

---

## [Integrate Events into Elastic SIEM](https://discuss.elastic.co/t/integrate-events-into-elastic-siem/224091)

<div class="topic-metadata">

**Author:** [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)\
**Replies:** 4\
**Last updated:** [March 22, 2020, 6:27pm UTC](https://discuss.elastic.co/t/integrate-events-into-elastic-siem/224091 "2020-03-22T18:27:09Z")

</div>

Hello guys, I´m new using ELK Stack. I have been parsing log data from Palo Alto Firewall and Cisco Umbrella by using Logstash to index it into Elasticsearch. It was a difficult task, because I have no experience doing…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=19)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=21)
