# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=22

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 23

---

## [Unable to start auditbeat for siem](https://discuss.elastic.co/t/unable-to-start-auditbeat-for-siem/213431)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 0\
**Last updated:** [December 31, 2019, 9:46am UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-for-siem/213431 "2019-12-31T09:46:25Z")

</div>

HI, im using elk stack of version 7.5.1 with x-pack installed and i cant able to start auditbeat for siem. Please help me solve it: Exiting: 2 errors: 1 error: failed to create audit client: failed to get audit status…

---

## [Howto change indices in def. ML jobs](https://discuss.elastic.co/t/howto-change-indices-in-def-ml-jobs/211620)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [December 20, 2019, 10:06am UTC](https://discuss.elastic.co/t/howto-change-indices-in-def-ml-jobs/211620 "2019-12-20T10:06:19Z")

</div>

Attempting to deploy std. SIEM ML jobs, only to find that they fail as they are meant for std. index naming. Issue is that we're using a custom named indices prefixed for a SIEM PoC. So question is how may we change the…

---

## [Our ML job stops execution with an exception: EmptyDataCountException: null](https://discuss.elastic.co/t/our-ml-job-stops-execution-with-an-exception-emptydatacountexception-null/212480)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [December 19, 2019, 2:58pm UTC](https://discuss.elastic.co/t/our-ml-job-stops-execution-with-an-exception-emptydatacountexception-null/212480 "2019-12-19T14:58:42Z")

</div>

Trying to run std. the various ML jobs for WIndows. Only two seems to keep running other stops again with exceptions like below. Wondering if exception happens maybe because we've still got to few sampled data yet? TIA …

---

## [SIEM Timeline data persistence and retention](https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [December 19, 2019, 7:15am UTC](https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344 "2019-12-19T07:15:20Z")

</div>

Playing a bit with SIEM App and wondering where are Timeline stored and how to possibly control their retention? Don't seem to find any godd system index candidates for this...

---

## [Elastic SIEM - Adding more data](https://discuss.elastic.co/t/elastic-siem-adding-more-data/212154)

<div class="topic-metadata">

**Author:** [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Replies:** 1\
**Last updated:** [December 17, 2019, 7:44pm UTC](https://discuss.elastic.co/t/elastic-siem-adding-more-data/212154 "2019-12-17T19:44:27Z")

</div>

HI There, Iam Elastic's SIEM for security analysis, but I would like to know if can add other datas to SIEM app, for example there are many logs sources sends syslog to my logstash .Can I have those logs as well in my E…

---

## [Auditbeat fileintegrity module cannot detect file update from vi](https://discuss.elastic.co/t/auditbeat-fileintegrity-module-cannot-detect-file-update-from-vi/211920)

<div class="topic-metadata">

**Author:** [@jittinan](https://discuss.elastic.co/u/jittinan)\
**Replies:** 0\
**Last updated:** [December 15, 2019, 7:00pm UTC](https://discuss.elastic.co/t/auditbeat-fileintegrity-module-cannot-detect-file-update-from-vi/211920 "2019-12-15T19:00:57Z")

</div>

from auditbeat documents,file integrity module detect changes by using inotify events from os.it works correctly with created,deleted,moved events by sending a message for each event to elasticserch but when the monitor…

---

## [I want to access the SIEM app without clicking the SIEM app](https://discuss.elastic.co/t/i-want-to-access-the-siem-app-without-clicking-the-siem-app/211122)

<div class="topic-metadata">

**Author:** [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Replies:** 2\
**Last updated:** [December 12, 2019, 12:04pm UTC](https://discuss.elastic.co/t/i-want-to-access-the-siem-app-without-clicking-the-siem-app/211122 "2019-12-12T12:04:29Z")

</div>

I have created a space , which has privileges for only SIEM app. Can I access the SIEM app directly without clicking the SIEM . I mean the SIEM app should automatically open

---

## [Anomaly detection Statuscode 404](https://discuss.elastic.co/t/anomaly-detection-statuscode-404/211142)

<div class="topic-metadata">

**Author:** [@MisterLamp](https://discuss.elastic.co/u/MisterLamp)\
**Replies:** 4\
**Last updated:** [December 12, 2019, 9:20am UTC](https://discuss.elastic.co/t/anomaly-detection-statuscode-404/211142 "2019-12-12T09:20:41Z")

</div>

Hi, we are running our elastic stack in version 7.3.2. A handful of clients has auditbeat installend and configured and I can see the data at SIEM. We have activated the trial license to use features like anomaly detec…

---

## [I want to enable the map which is present in SIEM app](https://discuss.elastic.co/t/i-want-to-enable-the-map-which-is-present-in-siem-app/211054)

<div class="topic-metadata">

**Author:** [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Replies:** 0\
**Last updated:** [December 9, 2019, 6:06am UTC](https://discuss.elastic.co/t/i-want-to-enable-the-map-which-is-present-in-siem-app/211054 "2019-12-09T06:06:19Z")

</div>

Hi , I am having Elasticsearch version 7.4, and in the SIEM app network section I want to enable the map present. I want to enable it through my own index , so i am doing ECS mapping of my index field but when i conve…

---

## [Error receiving audit reply: no buffer space available](https://discuss.elastic.co/t/error-receiving-audit-reply-no-buffer-space-available/210382)

<div class="topic-metadata">

**Author:** [@vaclav](https://discuss.elastic.co/u/vaclav)\
**Replies:** 1\
**Last updated:** [December 9, 2019, 9:28am UTC](https://discuss.elastic.co/t/error-receiving-audit-reply-no-buffer-space-available/210382 "2019-12-09T09:28:48Z")

</div>

Hello, I am having issue with auditbeat service running, but there is no output and some commands are not working. Found this error in syslog: auditbeat\[23346\]: 2019-12-03T11:48:38.116Z#011ERROR#011\[auditd\]#011auditd/a…

---

## [Authentication fields used by SIEM vs ECS](https://discuss.elastic.co/t/authentication-fields-used-by-siem-vs-ecs/210882)

<div class="topic-metadata">

**Author:** [@vbr](https://discuss.elastic.co/u/vbr)\
**Replies:** 3\
**Last updated:** [December 6, 2019, 5:04pm UTC](https://discuss.elastic.co/t/authentication-fields-used-by-siem-vs-ecs/210882 "2019-12-06T17:04:23Z")

</div>

Hi. We're storing security data in ES. We are not using the beats, but we are formatting data according to ECS. Unfortunately, the different values for fields are so far not well standardized, and working out how to get…

---

## [SIEM - Any overlap between filbeat ingesting syslog, auditlog, authlog and auditbeat (with auditd, system and FI modules)?](https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235)

<div class="topic-metadata">

**Author:** [@vsubrama](https://discuss.elastic.co/u/vsubrama)\
**Replies:** 2\
**Last updated:** [December 5, 2019, 10:26pm UTC](https://discuss.elastic.co/t/siem-any-overlap-between-filbeat-ingesting-syslog-auditlog-authlog-and-auditbeat-with-auditd-system-and-fi-modules/210235 "2019-12-05T22:26:14Z")

</div>

We are currently ingesting syslog, auditlog, authlog from our ubuntu systems via filebeat to Elasticsearch 7.4.2 as a part of build our SIEM. We are planning to add auditbeat with auditd, system and file integrity module…

---

## [Unable to start audit beat](https://discuss.elastic.co/t/unable-to-start-audit-beat/209594)

<div class="topic-metadata">

**Author:** [@Sudeep\_Khare](https://discuss.elastic.co/u/Sudeep_Khare)\
**Replies:** 0\
**Last updated:** [November 27, 2019, 1:38am UTC](https://discuss.elastic.co/t/unable-to-start-audit-beat/209594 "2019-11-27T01:38:14Z")

</div>

I am relatively new to ELK and I am trying to send logs from audit beat to Kibana. I have followed the steps from ELK documentation to install audit-beats on Linux . But at the last step when I run the audit beat I am ge…

---

## [An ECS compliant Kibana index pattern must be configured to view event data on the map](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969)

<div class="topic-metadata">

**Author:** [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Replies:** 4\
**Last updated:** [December 5, 2019, 2:02pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969 "2019-12-05T14:02:14Z")

</div>

Hi all, I am using Filebeat module cisco to get logs. I am not storing this logs in an index called filebeat-\* but cisco-\*. To get the correct mapping for this pattern, I exported the filebeat template and imported it f…

---

## [What field are used to populate the entire SIEM APP](https://discuss.elastic.co/t/what-field-are-used-to-populate-the-entire-siem-app/209263)

<div class="topic-metadata">

**Author:** [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Replies:** 2\
**Last updated:** [December 3, 2019, 9:42am UTC](https://discuss.elastic.co/t/what-field-are-used-to-populate-the-entire-siem-app/209263 "2019-12-03T09:42:01Z")

</div>

Hii Everyone, I am trying to map the fields used in my index to the ECS fields so that it gets populated in the SIEM APP. I have mapped fields like username , hostname and event action with the ECS fields and its gettin…

---

## [TheHIVE integration for SIEM Case Management](https://discuss.elastic.co/t/thehive-integration-for-siem-case-management/209129)

<div class="topic-metadata">

**Author:** [@ch3no2](https://discuss.elastic.co/u/ch3no2)\
**Replies:** 1\
**Last updated:** [November 29, 2019, 2:55pm UTC](https://discuss.elastic.co/t/thehive-integration-for-siem-case-management/209129 "2019-11-29T14:55:16Z")

</div>

In the last Elastic SIEM Presentation (11/21/2019), the presentation showed the integration with MISP... Is that the same MISP that is part of TheHive ? AND is there is there any consideration of having hooks in the SI…

---

## [Fielddata is disabled](https://discuss.elastic.co/t/fielddata-is-disabled/206816)

<div class="topic-metadata">

**Author:** [@Manoel](https://discuss.elastic.co/u/Manoel)\
**Replies:** 6\
**Last updated:** [November 28, 2019, 5:51pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816 "2019-11-28T17:51:20Z")

</div>

Hello. I upgraded from Elastic Stack version 6.8 to 7.4. I installed AudioBeat on all my servers, with the configuration below. auditbeat.modules: - module: auditd audit\_rule\_files: \[ '${path.config}/audit.rules.d/\*…

---

## [Auditbeat docker (7.4.2) starts and then terminates with no error](https://discuss.elastic.co/t/auditbeat-docker-7-4-2-starts-and-then-terminates-with-no-error/209348)

<div class="topic-metadata">

**Author:** [@yoshugo](https://discuss.elastic.co/u/yoshugo)\
**Replies:** 1\
**Last updated:** [November 26, 2019, 5:01pm UTC](https://discuss.elastic.co/t/auditbeat-docker-7-4-2-starts-and-then-terminates-with-no-error/209348 "2019-11-26T17:01:32Z")

</div>

Hi, i'm new to auditbeat. i've configured a test machine in my lab and configured all ELK stack as dockers. the Auditbeat starts and load dashboards and then stops.

---

## [Can Someone Help me Configure Suricata Filebeat on elastic cloud?](https://discuss.elastic.co/t/can-someone-help-me-configure-suricata-filebeat-on-elastic-cloud/208962)

<div class="topic-metadata">

**Author:** [@Wilfyboy](https://discuss.elastic.co/u/Wilfyboy)\
**Replies:** 1\
**Last updated:** [November 21, 2019, 6:56pm UTC](https://discuss.elastic.co/t/can-someone-help-me-configure-suricata-filebeat-on-elastic-cloud/208962 "2019-11-21T18:56:42Z")

</div>

Here are steps I followed to install Filebeats: "C:\\Program Files\\Filebeat" cd "C:\\Program Files\\Filebeat" Edited Elastic Cloud section filebeat.yml file to add cloud.id: and cloud.auth: filebeat.exe modules enable suri…

---

## [GCP VPC Flows in SIEM](https://discuss.elastic.co/t/gcp-vpc-flows-in-siem/208259)

<div class="topic-metadata">

**Author:** [@numbersix](https://discuss.elastic.co/u/numbersix)\
**Replies:** 2\
**Last updated:** [November 19, 2019, 2:16pm UTC](https://discuss.elastic.co/t/gcp-vpc-flows-in-siem/208259 "2019-11-19T14:16:08Z")

</div>

I have GCP VPC Flows in Elasticsearch but what is the easiest way to integrate them into the SIEM? I see net flow integrations available for other sources but not GCP. I'm using the Google Cloud Module for Filebeat cur…

---

## [SIEM not ingesting Forwarded Windows logs](https://discuss.elastic.co/t/siem-not-ingesting-forwarded-windows-logs/207311)

<div class="topic-metadata">

**Author:** [@mustdiee](https://discuss.elastic.co/u/mustdiee)\
**Replies:** 5\
**Last updated:** [November 14, 2019, 5:54pm UTC](https://discuss.elastic.co/t/siem-not-ingesting-forwarded-windows-logs/207311 "2019-11-14T17:54:34Z")

</div>

Hello! I'am collecting logs from all Windows PCs in my infrastructure with EventForwarding. Only one server has a winlogbeat installed, which is configured on other workstations as a subscription server (this is the eas…

---

## [In Ubuntu 18.04 auditbeat logs goes to syslog than /var/log/auditbeat](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 3\
**Last updated:** [November 13, 2019, 9:03pm UTC](https://discuss.elastic.co/t/in-ubuntu-18-04-auditbeat-logs-goes-to-syslog-than-var-log-auditbeat/206269 "2019-11-13T21:03:29Z")

</div>

Hi All, Good morning I am using Ubuntu 18.04 I have auditbeat installed and running on my system, in the auditbeat.yml files I have given the following logging.level: info path.logs: /var/log/auditbeat When I chec…

---

## [Metricbeat -c /etc/metricbeat.yml logs goes to the path specified , when stating with systemctl it does not](https://discuss.elastic.co/t/metricbeat-c-etc-metricbeat-yml-logs-goes-to-the-path-specified-when-stating-with-systemctl-it-does-not/206273)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 4\
**Last updated:** [November 13, 2019, 10:54am UTC](https://discuss.elastic.co/t/metricbeat-c-etc-metricbeat-yml-logs-goes-to-the-path-specified-when-stating-with-systemctl-it-does-not/206273 "2019-11-13T10:54:22Z")

</div>

Hi All, Good morning I am experiencing a strange observation here with logs when I run metricbeat -c /etc/metricbeat/metricbeat.yml the logs goes to the specified location else not going, ie when started as servic…

---

## [Kibana , displaying of hosts takes a lot of time \[ I have only few hosts 6 max\]](https://discuss.elastic.co/t/kibana-displaying-of-hosts-takes-a-lot-of-time-i-have-only-few-hosts-6-max/206004)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 1\
**Last updated:** [November 13, 2019, 10:45am UTC](https://discuss.elastic.co/t/kibana-displaying-of-hosts-takes-a-lot-of-time-i-have-only-few-hosts-6-max/206004 "2019-11-13T10:45:54Z")

</div>

Hi All, My kibana interaces displays the status of the machines very very slow, I do not have much hosts, 6 hosts for tesing purpose and it is taking too much time to display, I have added the screen shot for reference …

---

## [Add Another Reputation Link into Kibana SIEM](https://discuss.elastic.co/t/add-another-reputation-link-into-kibana-siem/205072)

<div class="topic-metadata">

**Author:** [@joshuasmith](https://discuss.elastic.co/u/joshuasmith)\
**Replies:** 1\
**Last updated:** [November 13, 2019, 10:42am UTC](https://discuss.elastic.co/t/add-another-reputation-link-into-kibana-siem/205072 "2019-11-13T10:42:56Z")

</div>

Hello, We are starting to use the SIEM app some more and wanted to add a few additional links for Threat Intel and context. What is the process for getting another customizable link (similar to the virustotal or talosi…

---

## [Zeek dns logs show only as zeek.notice leaving dns fields empty](https://discuss.elastic.co/t/zeek-dns-logs-show-only-as-zeek-notice-leaving-dns-fields-empty/207633)

<div class="topic-metadata">

**Author:** [@Dimitry\_Baranov](https://discuss.elastic.co/u/Dimitry_Baranov)\
**Replies:** 0\
**Last updated:** [November 13, 2019, 6:34am UTC](https://discuss.elastic.co/t/zeek-dns-logs-show-only-as-zeek-notice-leaving-dns-fields-empty/207633 "2019-11-13T06:34:52Z")

</div>

Hello everyone, Filebeat Zeek Module -\> Logstash -\> ES -\> Kibana SIEM 7.4.0 setup showing zeek DNS, SSL etc logs only as zeek.notice logs (e.g. instead of zeek.dns.query there are only zeek.notice.query). All the mappin…

---

## [Autonomous System Number (ASN) not displaying](https://discuss.elastic.co/t/autonomous-system-number-asn-not-displaying/206195)

<div class="topic-metadata">

**Author:** [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Replies:** 3\
**Last updated:** [November 1, 2019, 7:58pm UTC](https://discuss.elastic.co/t/autonomous-system-number-asn-not-displaying/206195 "2019-11-01T19:58:09Z")

</div>

I have an index that I've created that follows the ECS standard. Within the index I have the source.as.\* and destination.as.\* fields that are populated using the GeoLite2ASN database. The fields are being populated in …

---

## [Viewing Pinned Timeline Events](https://discuss.elastic.co/t/viewing-pinned-timeline-events/205132)

<div class="topic-metadata">

**Author:** [@MrTrav](https://discuss.elastic.co/u/MrTrav)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 6:57am UTC](https://discuss.elastic.co/t/viewing-pinned-timeline-events/205132 "2019-10-25T06:57:53Z")

</div>

Is it possible to only view events which have been pinned (marked as persisted with the timeline)?

---

## [Bulk ingest of netflow and zeek logs into Elastic SIEM](https://discuss.elastic.co/t/bulk-ingest-of-netflow-and-zeek-logs-into-elastic-siem/204746)

<div class="topic-metadata">

**Author:** [@cks](https://discuss.elastic.co/u/cks)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 3:07pm UTC](https://discuss.elastic.co/t/bulk-ingest-of-netflow-and-zeek-logs-into-elastic-siem/204746 "2019-10-24T15:07:17Z")

</div>

What would be best way to bulk ingest netflow and zeek logs into Elasticsearch, which I would like to access in SIEM in Kibana? I am looking to ingest several TBs of logs. I plan to bulk ingest other pcap, auth logs an…

---

## [New SIEM infrastructure with Elasticsearch](https://discuss.elastic.co/t/new-siem-infrastructure-with-elasticsearch/204559)

<div class="topic-metadata">

**Author:** [@elk2](https://discuss.elastic.co/u/elk2)\
**Replies:** 3\
**Last updated:** [October 22, 2019, 11:51pm UTC](https://discuss.elastic.co/t/new-siem-infrastructure-with-elasticsearch/204559 "2019-10-22T23:51:57Z")

</div>

I want to implement a new SIEM infrastructure for threat detection and incident response. I would host the systems in our datacenter where all others servers are hosted. I want to use beat to send logs from servers to …

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=21)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=23)
