# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=23

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 24

---

## [Problem with SIEM](https://discuss.elastic.co/t/problem-with-siem/204593)

<div class="topic-metadata">

**Author:** [@Aleix\_Abrie\_Prat](https://discuss.elastic.co/u/Aleix_Abrie_Prat)\
**Replies:** 7\
**Last updated:** [October 22, 2019, 4:52pm UTC](https://discuss.elastic.co/t/problem-with-siem/204593 "2019-10-22T16:52:42Z")

</div>

Hello everyone, I have a problem once i have configured SIEM and auditbeat on the "client" machine. I configured one machine only with auditbeat and the coniguration standars. I will post below the configuration. The …

---

## [For example, I have machine A running as a Server and I would like to manage other clients such as machine B, C, D,...etc So, how to do that? How to get many hosts?](https://discuss.elastic.co/t/for-example-i-have-machine-a-running-as-a-server-and-i-would-like-to-manage-other-clients-such-as-machine-b-c-d-etc-so-how-to-do-that-how-to-get-many-hosts/201330)

<div class="topic-metadata">

**Author:** [@pbona](https://discuss.elastic.co/u/pbona)\
**Replies:** 20\
**Last updated:** [October 22, 2019, 12:44am UTC](https://discuss.elastic.co/t/for-example-i-have-machine-a-running-as-a-server-and-i-would-like-to-manage-other-clients-such-as-machine-b-c-d-etc-so-how-to-do-that-how-to-get-many-hosts/201330 "2019-10-22T00:44:10Z")

</div>

---

## [How to change query in SIEM](https://discuss.elastic.co/t/how-to-change-query-in-siem/204113)

<div class="topic-metadata">

**Author:** [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Replies:** 2\
**Last updated:** [October 21, 2019, 2:32am UTC](https://discuss.elastic.co/t/how-to-change-query-in-siem/204113 "2019-10-21T02:32:36Z")

</div>

Im using Elastic stack 7.4 and stup auditbeat, filebeat, packetbeat ready. Im focus on SIEM -\> network, in Top DNS domains panel, i saw , default get top root domain not real domain. ( dns.question.registered\_domain ins…

---

## [SIEM not detecting ASA success failure logins](https://discuss.elastic.co/t/siem-not-detecting-asa-success-failure-logins/203754)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 5\
**Last updated:** [October 19, 2019, 5:31am UTC](https://discuss.elastic.co/t/siem-not-detecting-asa-success-failure-logins/203754 "2019-10-19T05:31:59Z")

</div>

SIEM not detecting success and failure logins from ASA syslog messages. and also it detect filebeat hostname as the host in SIEM app. What can i do? ASA Syslog message parsing could be better from filebeat 7.4 to popula…

---

## [Active Directory logs and mapping to ECS (I am stumped)](https://discuss.elastic.co/t/active-directory-logs-and-mapping-to-ecs-i-am-stumped/203321)

<div class="topic-metadata">

**Author:** [@iukea](https://discuss.elastic.co/u/iukea)\
**Replies:** 6\
**Last updated:** [October 14, 2019, 5:18pm UTC](https://discuss.elastic.co/t/active-directory-logs-and-mapping-to-ecs-i-am-stumped/203321 "2019-10-14T17:18:12Z")

</div>

Hello guys/girls, Need some words of wisdom on ECS and on Active Directory logs. I am currently logging a Windows server 2012 Domain controller and used to flowing guide (provided by ElasticSearch) - https://www.elast…

---

## [SIEM Command Line Auditing 4688 - 4689](https://discuss.elastic.co/t/siem-command-line-auditing-4688-4689/202656)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 10\
**Last updated:** [October 14, 2019, 1:01pm UTC](https://discuss.elastic.co/t/siem-command-line-auditing-4688-4689/202656 "2019-10-14T13:01:09Z")

</div>

Hello, 2 of the most interesting event id's in siem are 4688 and 4689, which can be enabled with a gpo and enable us to monitor every command used in your network. Interesting fields are: winlog.event\_data.NewProcessN…

---

## [How to get more hosts in SIEM (Auditbeat)](https://discuss.elastic.co/t/how-to-get-more-hosts-in-siem-auditbeat/201904)

<div class="topic-metadata">

**Author:** [@pbona](https://discuss.elastic.co/u/pbona)\
**Replies:** 1\
**Last updated:** [October 2, 2019, 11:45am UTC](https://discuss.elastic.co/t/how-to-get-more-hosts-in-siem-auditbeat/201904 "2019-10-02T11:45:39Z")

</div>

---

## [Defenxor DSIEM for Event Correlation with Logstash](https://discuss.elastic.co/t/defenxor-dsiem-for-event-correlation-with-logstash/201649)

<div class="topic-metadata">

**Author:** [@gargantua](https://discuss.elastic.co/u/gargantua)\
**Replies:** 0\
**Last updated:** [September 30, 2019, 1:47pm UTC](https://discuss.elastic.co/t/defenxor-dsiem-for-event-correlation-with-logstash/201649 "2019-09-30T13:47:04Z")

</div>

Hello, I want to correlate my events with defenxor/dsiem. Is there anyone who uses dsiem for event correlation? Is it enough for correlation? What are advantages and disadvantages of dsiem?

---

## [SIEM Infrastructure design](https://discuss.elastic.co/t/siem-infrastructure-design/201529)

<div class="topic-metadata">

**Author:** [@lokmanopt](https://discuss.elastic.co/u/lokmanopt)\
**Replies:** 1\
**Last updated:** [September 30, 2019, 10:35am UTC](https://discuss.elastic.co/t/siem-infrastructure-design/201529 "2019-09-30T10:35:24Z")

</div>

Dear Concern, I want to implement SIEM solution for production. I need to ELK expert's help Please share Design for production environment. I have more then 300 system and 300 router as well as 6 Cisco firewall. So p…

---

## [Filter Uncommon Host Processes](https://discuss.elastic.co/t/filter-uncommon-host-processes/197874)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [September 27, 2019, 11:05am UTC](https://discuss.elastic.co/t/filter-uncommon-host-processes/197874 "2019-09-27T11:05:11Z")

</div>

Hello, Read here (https://discuss.elastic.co/t/uncommon-processes/190115) that the Uncommon Processes query is an aggregation on process.name sorted by host cardinality first (cardinality of host.name where this pro…

---

## [Hash used in Elastic?](https://discuss.elastic.co/t/hash-used-in-elastic/201326)

<div class="topic-metadata">

**Author:** [@zeno](https://discuss.elastic.co/u/zeno)\
**Replies:** 2\
**Last updated:** [September 27, 2019, 10:49am UTC](https://discuss.elastic.co/t/hash-used-in-elastic/201326 "2019-09-27T10:49:08Z")

</div>

Hi so i am studying and using Kibana open source and wanted to know whether kibana open source by default creates hashes of files ? The document of elastic says that it does use SHA256, SHA-1 & MD5 but as per the auditbe…

---

## [SIEM ECS descriptions taking huge amount of unneccesary space in SIEM](https://discuss.elastic.co/t/siem-ecs-descriptions-taking-huge-amount-of-unneccesary-space-in-siem/200972)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [September 27, 2019, 10:27am UTC](https://discuss.elastic.co/t/siem-ecs-descriptions-taking-huge-amount-of-unneccesary-space-in-siem/200972 "2019-09-27T10:27:59Z")

</div>

Hello, Just some constructive feedback. When data is added to a SIEM timeline and the results are analyzed, it seems every field has a description column, which imho takes a huge amount of space, which could be used for…

---

## [How many swap files are created when you update a text file](https://discuss.elastic.co/t/how-many-swap-files-are-created-when-you-update-a-text-file/197625)

<div class="topic-metadata">

**Author:** [@zeno](https://discuss.elastic.co/u/zeno)\
**Replies:** 8\
**Last updated:** [September 26, 2019, 7:16am UTC](https://discuss.elastic.co/t/how-many-swap-files-are-created-when-you-update-a-text-file/197625 "2019-09-26T07:16:18Z")

</div>

I want to know how many swap files are created in kibana for Ubuntu server when you create a text file using nano. i see 4 swap files deleted when i deleted the text file i have created in Ubuntu. Similarly the no of swa…

---

## [Add additional data source to SIEM dashboard](https://discuss.elastic.co/t/add-additional-data-source-to-siem-dashboard/199712)

<div class="topic-metadata">

**Author:** [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Replies:** 3\
**Last updated:** [September 18, 2019, 8:46am UTC](https://discuss.elastic.co/t/add-additional-data-source-to-siem-dashboard/199712 "2019-09-18T08:46:35Z")

</div>

Is there a way to add additional data sources to the SIEM dashboard? I have an index, syslog-, that collects data from our network switches & firewalls. It does use the ECS conventions. The dashboard seems to only use…

---

## [Hosts tab in SIEM and WEF](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162)

<div class="topic-metadata">

**Author:** [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Replies:** 16\
**Last updated:** [September 16, 2019, 2:25pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162 "2019-09-16T14:25:58Z")

</div>

There is Hosts tab in SIEM. I think nobody in Enterprise uses Winlogbeat on every Windows hosts. It is standard to use collector for logs and send Logs using Windows Event Forwarding on it. So, in field Host it will be n…

---

## [SonicWall Firewall and SIEM or SNMP](https://discuss.elastic.co/t/sonicwall-firewall-and-siem-or-snmp/199546)

<div class="topic-metadata">

**Author:** [@jabalo1327](https://discuss.elastic.co/u/jabalo1327)\
**Replies:** 1\
**Last updated:** [September 15, 2019, 5:49pm UTC](https://discuss.elastic.co/t/sonicwall-firewall-and-siem-or-snmp/199546 "2019-09-15T17:49:30Z")

</div>

How Do I configure my sonicwall firewall to send all the logs to the cloud for this product and what product Do I actually need? Is there any approximate price range for month? I will like to see all the data that my s…

---

## [Envoyproxy](https://discuss.elastic.co/t/envoyproxy/195755)

<div class="topic-metadata">

**Author:** [@mcapua](https://discuss.elastic.co/u/mcapua)\
**Replies:** 2\
**Last updated:** [September 7, 2019, 7:18am UTC](https://discuss.elastic.co/t/envoyproxy/195755 "2019-09-07T07:18:28Z")

</div>

Hello, I'm trying to send envoyproxy logs to SIEM but I'm receiving a WARN message. ISTIO was configured with stdout access logs and running on Kubernetes \> Finished:false, Fileinfo:(\*os.fileStat)(0xc0035c2ea0), Sourc…

---

## [Fielddata error preventing Authentications tab populating](https://discuss.elastic.co/t/fielddata-error-preventing-authentications-tab-populating/197337)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 3\
**Last updated:** [September 4, 2019, 3:41am UTC](https://discuss.elastic.co/t/fielddata-error-preventing-authentications-tab-populating/197337 "2019-09-04T03:41:04Z")

</div>

Hi all, I'm using Filebeat 7.3.1 with Elastic Cloud 7.3.0 and the Authentications pane (in SIEM app) is empty (despite being able to view them in Discover / filebeat index. When I inspect the response in the SIEM app I…

---

## [PoC - Use ELK to aggregate multiple LogInsight Systems into one SOC](https://discuss.elastic.co/t/poc-use-elk-to-aggregate-multiple-loginsight-systems-into-one-soc/196615)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [September 3, 2019, 11:45am UTC](https://discuss.elastic.co/t/poc-use-elk-to-aggregate-multiple-loginsight-systems-into-one-soc/196615 "2019-09-03T11:45:16Z")

</div>

I've personally in the last 3-4 years been using Grafana+ELK for Log&Metric monitoring in running a large application platform, but have now changed internally to a position in Security & Operation Automation and are her…

---

## [Siem on logstash and filebeat](https://discuss.elastic.co/t/siem-on-logstash-and-filebeat/196523)

<div class="topic-metadata">

**Author:** [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Replies:** 1\
**Last updated:** [August 30, 2019, 12:49pm UTC](https://discuss.elastic.co/t/siem-on-logstash-and-filebeat/196523 "2019-08-30T12:49:21Z")

</div>

Hi..I am sending netflow data to my server via filebeat and the indices are successfully created as well as its implemented on siem too. But there are many information which are unavailable like geo location, protocols n…

---

## [Event Correlation on ELK](https://discuss.elastic.co/t/event-correlation-on-elk/194362)

<div class="topic-metadata">

**Author:** [@alperensoydan](https://discuss.elastic.co/u/alperensoydan)\
**Replies:** 2\
**Last updated:** [August 26, 2019, 12:07pm UTC](https://discuss.elastic.co/t/event-correlation-on-elk/194362 "2019-08-26T12:07:08Z")

</div>

Hello, I installed ELK as a SIEM and It works nicely. There is only one problem is that correlation of different events and it does not come default within ELK. According to my researches, Logstash filters work for this…

---

## [GraphQL internal error](https://discuss.elastic.co/t/graphql-internal-error/195405)

<div class="topic-metadata">

**Author:** [@j13029](https://discuss.elastic.co/u/j13029)\
**Replies:** 1\
**Last updated:** [August 19, 2019, 10:24am UTC](https://discuss.elastic.co/t/graphql-internal-error/195405 "2019-08-19T10:24:20Z")

</div>

I am currently getting some error messages under SIEM menus. "Unable to parse JSON \< at line 52" Checking the network logs, this call seems to be failing along. It would sometimes go through and sometimes fail. What c…

---

## [Difference between source/destination and server/client](https://discuss.elastic.co/t/difference-between-source-destination-and-server-client/195075)

<div class="topic-metadata">

**Author:** [@vbr](https://discuss.elastic.co/u/vbr)\
**Replies:** 1\
**Last updated:** [August 16, 2019, 1:48pm UTC](https://discuss.elastic.co/t/difference-between-source-destination-and-server-client/195075 "2019-08-16T13:48:35Z")

</div>

Hi. I'm currently evaluating the SIEM app for integration in our security workflows, and converting most of our datasets to ECS for that purpose. I'm puzzled by the existence of both client/server and source/destination…

---

## [I'm not seeing any geoip data from my zeek logs in my SIEM map](https://discuss.elastic.co/t/im-not-seeing-any-geoip-data-from-my-zeek-logs-in-my-siem-map/194677)

<div class="topic-metadata">

**Author:** [@dpangallo](https://discuss.elastic.co/u/dpangallo)\
**Replies:** 2\
**Last updated:** [August 12, 2019, 5:09pm UTC](https://discuss.elastic.co/t/im-not-seeing-any-geoip-data-from-my-zeek-logs-in-my-siem-map/194677 "2019-08-12T17:09:08Z")

</div>

I'm using Filebeats 7.3.0 to ingest Zeek network logs into Elasticsearch 7.3.0, but I'm not seeing any geoip fields created in my indexes. The Zeek ingest module automatically created pipelines for each of the different…

---

## [Filebeat for Sophos XG Firewall](https://discuss.elastic.co/t/filebeat-for-sophos-xg-firewall/192952)

<div class="topic-metadata">

**Author:** [@kal1s](https://discuss.elastic.co/u/kal1s)\
**Replies:** 8\
**Last updated:** [August 7, 2019, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-for-sophos-xg-firewall/192952 "2019-08-07T16:15:41Z")

</div>

Hi, Will be possible to have Filebeat for Sophos XG FIrewall and integrated with Elastic SIEM like Filebeat Cisco? Best Regards, Ricardo Calimanis

---

## [Why don't sudo events from auth.log have an event.category/event.action?](https://discuss.elastic.co/t/why-dont-sudo-events-from-auth-log-have-an-event-category-event-action/193911)

<div class="topic-metadata">

**Author:** [@agx](https://discuss.elastic.co/u/agx)\
**Replies:** 1\
**Last updated:** [August 7, 2019, 11:10am UTC](https://discuss.elastic.co/t/why-dont-sudo-events-from-auth-log-have-an-event-category-event-action/193911 "2019-08-07T11:10:21Z")

</div>

Hello, I've been exploring the new SIEM features in 7.3 and am pretty excited about promoting ECS at work. I noticed that when ingesting my auth logs from Ubuntu 18.04 using the system module included with filebeat, th…

---

## [SIEM Hosts/All Hosts Tables Empty](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 11\
**Last updated:** [August 5, 2019, 1:03pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832 "2019-08-05T13:03:12Z")

</div>

Started playing with SIEM after upgrading our Stack and some agents to 7.2. I currently have winlogbeat and auditbeat sending data to our stack. Auditbeat has the host and process modules enabled, winlogbeat is sending…

---

## [Watcher alert, ssh auth](https://discuss.elastic.co/t/watcher-alert-ssh-auth/191969)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 1\
**Last updated:** [July 31, 2019, 6:27am UTC](https://discuss.elastic.co/t/watcher-alert-ssh-auth/191969 "2019-07-31T06:27:54Z")

</div>

hey there, i'm new using elastic and i just wanna asking about alerting. i make an alert through email. but i don't know how the user id showed up at body email and the count the user try. btw this for ssh auth. thanks

---

## [Empty DNS Fields and Tables in Network View](https://discuss.elastic.co/t/empty-dns-fields-and-tables-in-network-view/192285)

<div class="topic-metadata">

**Author:** [@pepperhat](https://discuss.elastic.co/u/pepperhat)\
**Replies:** 1\
**Last updated:** [July 30, 2019, 8:21am UTC](https://discuss.elastic.co/t/empty-dns-fields-and-tables-in-network-view/192285 "2019-07-30T08:21:02Z")

</div>

I have working with the new SIEM module in 7.2 and have been consuming Suricata data with the filebeat module. When reviewing the data in the SIEM view, some fields and tables are empty, where I would expect data to show…

---

## [Having SIEM read windows events from non-default index pattern](https://discuss.elastic.co/t/having-siem-read-windows-events-from-non-default-index-pattern/192496)

<div class="topic-metadata">

**Author:** [@tyler\_hilsabeck](https://discuss.elastic.co/u/tyler_hilsabeck)\
**Replies:** 2\
**Last updated:** [July 29, 2019, 12:47pm UTC](https://discuss.elastic.co/t/having-siem-read-windows-events-from-non-default-index-pattern/192496 "2019-07-29T12:47:19Z")

</div>

Hi Everyone, I do not store my winlogbeat data in the default named indexes (winlogbeat-\*) but rather windows\_logs-\* for ease of management with ILM, log type clarity, etc. I have installed the default kibana dashboard…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=22)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=24)
