# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=21

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 22

---

## [Kibana SIEM "External Alert"](https://discuss.elastic.co/t/kibana-siem-external-alert/220643)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [March 19, 2020, 11:11am UTC](https://discuss.elastic.co/t/kibana-siem-external-alert/220643 "2020-03-19T11:11:43Z")

</div>

Hello, I was wondering how we can use the 'External Alert' functionality in Kibana SIEM 7.6.0? The documentation is rather sparse (https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#\_signa…

---

## [Kibana SIEM application is not displaying proper AS and GeoIP fields](https://discuss.elastic.co/t/kibana-siem-application-is-not-displaying-proper-as-and-geoip-fields/223972)

<div class="topic-metadata">

**Author:** [@Gmexican14](https://discuss.elastic.co/u/Gmexican14)\
**Replies:** 0\
**Last updated:** [March 17, 2020, 4:23pm UTC](https://discuss.elastic.co/t/kibana-siem-application-is-not-displaying-proper-as-and-geoip-fields/223972 "2020-03-17T16:23:00Z")

</div>

Hello everyone, I am having an issue when it comes to displaying GeoIP fields and AS fields in the SIEM app within Kibana. I have made sure that the fields get remapped to the appropriate ECS fields. As seen in the scr…

---

## [Host not showing up despite events being present](https://discuss.elastic.co/t/host-not-showing-up-despite-events-being-present/223105)

<div class="topic-metadata">

**Author:** [@norup](https://discuss.elastic.co/u/norup)\
**Replies:** 8\
**Last updated:** [March 13, 2020, 1:49pm UTC](https://discuss.elastic.co/t/host-not-showing-up-despite-events-being-present/223105 "2020-03-13T13:49:05Z")

</div>

I am running the elk stack on 1 ubuntu device along with filebeat, and metricbeat and this device is showing up fine with syslog data and as a host. Im running winlogbeat on another device, and shipping the logs through …

---

## [UEBA for elk](https://discuss.elastic.co/t/ueba-for-elk/223353)

<div class="topic-metadata">

**Author:** [@oumy](https://discuss.elastic.co/u/oumy)\
**Replies:** 2\
**Last updated:** [March 13, 2020, 7:54am UTC](https://discuss.elastic.co/t/ueba-for-elk/223353 "2020-03-13T07:54:06Z")

</div>

hello there is there an opensource UEBA that can be integrated with Elastic stack? and also a Netework monitoring tools

---

## [PFSense Data and ECS - Data Fetch Failure](https://discuss.elastic.co/t/pfsense-data-and-ecs-data-fetch-failure/222525)

<div class="topic-metadata">

**Author:** [@somm15](https://discuss.elastic.co/u/somm15)\
**Replies:** 1\
**Last updated:** [March 10, 2020, 9:29am UTC](https://discuss.elastic.co/t/pfsense-data-and-ecs-data-fetch-failure/222525 "2020-03-10T09:29:07Z")

</div>

Hello, I am ingesting my PFSense logs and net flow using Filebeat. Filebeat feeds LogStash and it does the enrichment with select parts of the code from there: It works pretty well, each data type in its own index. …

---

## [7.6.0 vs new signals and futher enrich ingestion](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 9\
**Last updated:** [February 17, 2020, 8:14am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211 "2020-02-17T08:14:17Z")

</div>

Just updated our cluster to 7.6.0 and are wondering where to read up on utilizing the new SIEM signals and if needed how to do further ingestion enriching to enhance signals eta. Currently got winlog(+sysmon) and audit …

---

## [Alerting with actions in SIEM Detection Rules](https://discuss.elastic.co/t/alerting-with-actions-in-siem-detection-rules/221595)

<div class="topic-metadata">

**Author:** [@Or\_Biran](https://discuss.elastic.co/u/Or_Biran)\
**Replies:** 3\
**Last updated:** [March 6, 2020, 9:47pm UTC](https://discuss.elastic.co/t/alerting-with-actions-in-siem-detection-rules/221595 "2020-03-06T21:47:04Z")

</div>

Hi, I'm trying to understand how can I add alerts with actions like Slack to the SIEM rules... The only way I found is to add a Watcher on the .siem indice.. but its not it, I want to get an actual alert to Slack with …

---

## [Data not showing in SIEM, Fielddata is disabled on text fields by default](https://discuss.elastic.co/t/data-not-showing-in-siem-fielddata-is-disabled-on-text-fields-by-default/222485)

<div class="topic-metadata">

**Author:** [@eturner](https://discuss.elastic.co/u/eturner)\
**Replies:** 0\
**Last updated:** [March 6, 2020, 4:07pm UTC](https://discuss.elastic.co/t/data-not-showing-in-siem-fielddata-is-disabled-on-text-fields-by-default/222485 "2020-03-06T16:07:05Z")

</div>

Hi all I've been playing around with ELK at work for viewing our windows logs but not all the data is showing up in the SIEM module. It seems to be having an issue grabbing it with a "Fielddata is disabled on text fiel…

---

## [Building a SIEM, need help](https://discuss.elastic.co/t/building-a-siem-need-help/222007)

<div class="topic-metadata">

**Author:** [@oumy](https://discuss.elastic.co/u/oumy)\
**Replies:** 5\
**Last updated:** [March 5, 2020, 7:50am UTC](https://discuss.elastic.co/t/building-a-siem-need-help/222007 "2020-03-05T07:50:45Z")

</div>

Hello there i amtrying to build a SIEM using open source tools. using ELK, Suricata for IDS, My sql as a DB, Ngnix as web server, Opendistro for alerting and still developping the architecture. i would apreciate your h…

---

## [SIEM - "All Hosts" Not showing Operating System](https://discuss.elastic.co/t/siem-all-hosts-not-showing-operating-system/221877)

<div class="topic-metadata">

**Author:** [@markbgale](https://discuss.elastic.co/u/markbgale)\
**Replies:** 0\
**Last updated:** [March 3, 2020, 11:54am UTC](https://discuss.elastic.co/t/siem-all-hosts-not-showing-operating-system/221877 "2020-03-03T11:54:13Z")

</div>

Hi All I'm running Elastic, Beats and Kibana version 7.5.2. In SIEM under the "All Hosts" tabs the servers are listed but the Operating System and Version is showing as a dash (-). If I drill into the server it gives …

---

## [Shards failed warning on Network dashboard in SIEM app](https://discuss.elastic.co/t/shards-failed-warning-on-network-dashboard-in-siem-app/219908)

<div class="topic-metadata">

**Author:** [@wconnell](https://discuss.elastic.co/u/wconnell)\
**Replies:** 8\
**Last updated:** [March 3, 2020, 12:04am UTC](https://discuss.elastic.co/t/shards-failed-warning-on-network-dashboard-in-siem-app/219908 "2020-03-03T00:04:40Z")

</div>

Hi there, I'm getting a shards failed warning in the Network dashboard of the SIEM app (v7.6). I'm unable to diagnose as when I click the "Show details" button, nothing happens. I used the inspect tool in Chrome and it …

---

## [Elasticsearch SIEM Dashboard](https://discuss.elastic.co/t/elasticsearch-siem-dashboard/221517)

<div class="topic-metadata">

**Author:** [@yfataar](https://discuss.elastic.co/u/yfataar)\
**Replies:** 1\
**Last updated:** [March 1, 2020, 11:31pm UTC](https://discuss.elastic.co/t/elasticsearch-siem-dashboard/221517 "2020-03-01T23:31:19Z")

</div>

Hi I have a Cisco Firewall (ASA) logging data to Filebeats -\> Logstash -\> Elasticsearch. I can see the syslog data in "Discover" section however I do not have any output in SIEM section under Networks. How does the data…

---

## [How to apply log retention policies to Elastic SIEM](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796)

<div class="topic-metadata">

**Author:** [@anon67583212](https://discuss.elastic.co/u/anon67583212)\
**Replies:** 3\
**Last updated:** [March 1, 2020, 10:06am UTC](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796 "2020-03-01T10:06:30Z")

</div>

Good morning, I am doing some tests with the product and I have just come across something, at least inconsistent: you cannot apply granular log retention policies. I mean, if you want to apply a 30-day retention policy…

---

## [Detection Custom Rule not working](https://discuss.elastic.co/t/detection-custom-rule-not-working/220856)

<div class="topic-metadata">

**Author:** [@Or\_Biran](https://discuss.elastic.co/u/Or_Biran)\
**Replies:** 17\
**Last updated:** [February 29, 2020, 2:25am UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/220856 "2020-02-29T02:25:14Z")

</div>

Hi, I'm trying to create a basic custom rule on a custom index that contains logs that originated from filebeat. creating a basic rule on that index just not working, no Signals created. Using the same query showing r…

---

## [SIEM App does not display Hostnames from Beats Events](https://discuss.elastic.co/t/siem-app-does-not-display-hostnames-from-beats-events/220330)

<div class="topic-metadata">

**Author:** [@cknoell](https://discuss.elastic.co/u/cknoell)\
**Replies:** 5\
**Last updated:** [February 21, 2020, 10:12pm UTC](https://discuss.elastic.co/t/siem-app-does-not-display-hostnames-from-beats-events/220330 "2020-02-21T22:12:36Z")

</div>

Hi, we have some problems using the SIEM App and Displaying Hostnames on the Hosts Page if it comes to a setup where you use: Beats -\> Logstash -\> Logstash -\> Elastic All components are using up to date V7.6.0 Beats…

---

## [Anomaly detection - Elastic Jobs failing to start](https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015)

<div class="topic-metadata">

**Author:** [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Replies:** 2\
**Last updated:** [February 21, 2020, 8:55pm UTC](https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015 "2020-02-21T20:55:04Z")

</div>

When I attempt to create an ML job using one of the pre-defined jobs for instance "windows\_rare\_user\_type10\_remote\_login", I receive the below error: \[status\_exception\] \[datafeed-windows\_rare\_user\_type10\_remote\_login\] c…

---

## [SIEM Hosts / Networks and Data Not Showing Up](https://discuss.elastic.co/t/siem-hosts-networks-and-data-not-showing-up/219848)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 4\
**Last updated:** [February 19, 2020, 4:16pm UTC](https://discuss.elastic.co/t/siem-hosts-networks-and-data-not-showing-up/219848 "2020-02-19T16:16:10Z")

</div>

New to SIEM. Confused about functionality or my settings. I have Fortinet and Sonicwall logs going to ES, via syslog to Logstash, then to ES. When I go to Elastic SIEM, under either Hosts or Network pages, I see nothin…

---

## [Hosts table : host.name (alias of beat.name) used instead of agent.hostname](https://discuss.elastic.co/t/hosts-table-host-name-alias-of-beat-name-used-instead-of-agent-hostname/219088)

<div class="topic-metadata">

**Author:** [@Georgios\_Gkinis](https://discuss.elastic.co/u/Georgios_Gkinis)\
**Replies:** 1\
**Last updated:** [February 17, 2020, 8:10pm UTC](https://discuss.elastic.co/t/hosts-table-host-name-alias-of-beat-name-used-instead-of-agent-hostname/219088 "2020-02-17T20:10:19Z")

</div>

I am using beats to forward metrics and logs to Elasticsearch. In the configuration of each beat I have setup its name manually : name: "${COMPUTERNAME}-filebeat-applications" When I go to SIEM -\> Hosts -\> table All H…

---

## [Threat signatures from observers](https://discuss.elastic.co/t/threat-signatures-from-observers/218962)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 4\
**Last updated:** [February 17, 2020, 1:29pm UTC](https://discuss.elastic.co/t/threat-signatures-from-observers/218962 "2020-02-17T13:29:53Z")

</div>

External security products, such as endpoint protection etc., often send a threat signature with their alerts ("Trojan.generic.823719237", "CVE-XXX-XXX Joomla SQL Injection"). Where do we put this threat name / signature…

---

## ["path: /\_security/api\_key... api keys are not enabled" while loading prebuilt detection rules](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319)

<div class="topic-metadata">

**Author:** [@Slavik\_Fursov](https://discuss.elastic.co/u/Slavik_Fursov)\
**Replies:** 3\
**Last updated:** [February 16, 2020, 10:33am UTC](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319 "2020-02-16T10:33:59Z")

</div>

I upgraded to 7.6.0 today. I wanted to try Detections, but I'm getting error (below) when clicking "load prebuilt detection rules". My complete Kibana config: --- ## Default Kibana configuration from Kibana base image…

---

## [AquaSec / TwistLock features for containers?](https://discuss.elastic.co/t/aquasec-twistlock-features-for-containers/219388)

<div class="topic-metadata">

**Author:** [@elenoir](https://discuss.elastic.co/u/elenoir)\
**Replies:** 0\
**Last updated:** [February 14, 2020, 2:45pm UTC](https://discuss.elastic.co/t/aquasec-twistlock-features-for-containers/219388 "2020-02-14T14:45:48Z")

</div>

Hi, I was wondering if you plan to develop some features such as AquaSec or TwistLock provides for containers? I think this question is valuable since the Endgame buying as Elastic could cover almost the whole perimet…

---

## [SIEM app doesn't use Timezone setting](https://discuss.elastic.co/t/siem-app-doesnt-use-timezone-setting/216906)

<div class="topic-metadata">

**Author:** [@wconnell](https://discuss.elastic.co/u/wconnell)\
**Replies:** 12\
**Last updated:** [February 14, 2020, 4:28am UTC](https://discuss.elastic.co/t/siem-app-doesnt-use-timezone-setting/216906 "2020-02-14T04:28:39Z")

</div>

I set the "Timezone for date formatting" to UTC in the Advanced settings, so all my dashboards and visualizations use it as expected. However the SIEM app seems to use the browser settings which throws things off. Is the…

---

## [Auditbeat omniscience?](https://discuss.elastic.co/t/auditbeat-omniscience/218695)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 1\
**Last updated:** [February 13, 2020, 6:13pm UTC](https://discuss.elastic.co/t/auditbeat-omniscience/218695 "2020-02-13T18:13:26Z")

</div>

I have an event picked up by Auditbeat where it registers a tcp connection to my machine (port 22 where openssh is listening) from an external source. That's fine and dandy however it claims to know what the process and…

---

## [Server send security events with WEF and in Authentication tab I don't found all accesses](https://discuss.elastic.co/t/server-send-security-events-with-wef-and-in-authentication-tab-i-dont-found-all-accesses/219221)

<div class="topic-metadata">

**Author:** [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Replies:** 0\
**Last updated:** [February 13, 2020, 2:02pm UTC](https://discuss.elastic.co/t/server-send-security-events-with-wef-and-in-authentication-tab-i-dont-found-all-accesses/219221 "2020-02-13T14:02:37Z")

</div>

Hi all I'm using Elastic Stack v7.4.0 and I have a single winlogbeat on the Windows Server that receive with WEF all event of security of differents other server. So I just correct by logstash, that I used to filter al…

---

## [Failed to installed pre-packaged rules from elastic](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111)

<div class="topic-metadata">

**Author:** [@wlzylal](https://discuss.elastic.co/u/wlzylal)\
**Replies:** 3\
**Last updated:** [February 13, 2020, 9:44am UTC](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111 "2020-02-13T09:44:07Z")

</div>

I have just upgrade my elk to 7.6.0 and I want to test the rules in SIEM, but I just can't load prebuilt detection rules. It said that // Your visualization has error(s) Failed to installed pre-packaged rules from elas…

---

## [SIEM \> Detections will not setup](https://discuss.elastic.co/t/siem-detections-will-not-setup/219035)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 1\
**Last updated:** [February 12, 2020, 3:56pm UTC](https://discuss.elastic.co/t/siem-detections-will-not-setup/219035 "2020-02-12T15:56:31Z")

</div>

Hi, I have upgraded to 7.6, going to SIEM \> Detections it comes up with Let's set up your detection engine. I have logged in as a superuser, event created a user with superuser and kibana-admin rights, still no change,…

---

## [Uploading third-party JSON output](https://discuss.elastic.co/t/uploading-third-party-json-output/218640)

<div class="topic-metadata">

**Author:** [@carenas](https://discuss.elastic.co/u/carenas)\
**Replies:** 1\
**Last updated:** [February 10, 2020, 9:03pm UTC](https://discuss.elastic.co/t/uploading-third-party-json-output/218640 "2020-02-10T21:03:28Z")

</div>

We are looking to analyze client log data that is exported (as JSON) from third-party SIEM products. Can this exported data be ingested as-is by Elastic SIEM and properly parsed? Or would we have to manually convert it…

---

## [Conflict between ECS and SIEM authentication events visualization](https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936)

<div class="topic-metadata">

**Author:** [@wconnell](https://discuss.elastic.co/u/wconnell)\
**Replies:** 2\
**Last updated:** [January 29, 2020, 7:16pm UTC](https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936 "2020-01-29T19:16:31Z")

</div>

On the Host tab of the SIEM app, there's a visualization that counts authentication events using the following logic: { "aggs": { "authentication\_success": { "filter": { "term": { "event.ty…

---

## [Elastic Integration with Zscaler NSS service](https://discuss.elastic.co/t/elastic-integration-with-zscaler-nss-service/211858)

<div class="topic-metadata">

**Author:** [@mountainreef](https://discuss.elastic.co/u/mountainreef)\
**Replies:** 1\
**Last updated:** [January 18, 2020, 4:38am UTC](https://discuss.elastic.co/t/elastic-integration-with-zscaler-nss-service/211858 "2020-01-18T04:38:00Z")

</div>

Hi, New here so apologies if this has been asked before? Has anyone integrated their stack with Zscalers Nanolog or NSS service for SIEM? If so is there any beats advice for connectivity, normalisation or community rule…

---

## [Siem anomaly detection prebuild jobs](https://discuss.elastic.co/t/siem-anomaly-detection-prebuild-jobs/213416)

<div class="topic-metadata">

**Author:** [@jittinan](https://discuss.elastic.co/u/jittinan)\
**Replies:** 1\
**Last updated:** [January 2, 2020, 4:07pm UTC](https://discuss.elastic.co/t/siem-anomaly-detection-prebuild-jobs/213416 "2020-01-02T16:07:49Z")

</div>

I am using trial version.I have installed filebeat,auditbeat,winlogbeat agent on target systems. The prebuilt jobs which i can use are siem-api-rare\_process\_linux\_ecs siem-api-rare\_process\_windows\_ecs 3.siem-api-suspi…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=20)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=22)
