# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=24

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 25

---

## [Zeek DNS Logs Into Top DNS Domains Section](https://discuss.elastic.co/t/zeek-dns-logs-into-top-dns-domains-section/191888)

<div class="topic-metadata">

**Author:** [@MrTrav](https://discuss.elastic.co/u/MrTrav)\
**Replies:** 1\
**Last updated:** [July 29, 2019, 10:35am UTC](https://discuss.elastic.co/t/zeek-dns-logs-into-top-dns-domains-section/191888 "2019-07-29T10:35:29Z")

</div>

Is there a way to get the data from the Zeek DNS logs into the Top DNS Domains panel in the SIEM?

---

## [Inserting Custom Logs Into Siem](https://discuss.elastic.co/t/inserting-custom-logs-into-siem/190093)

<div class="topic-metadata">

**Author:** [@MrTrav](https://discuss.elastic.co/u/MrTrav)\
**Replies:** 3\
**Last updated:** [July 23, 2019, 11:00am UTC](https://discuss.elastic.co/t/inserting-custom-logs-into-siem/190093 "2019-07-23T11:00:12Z")

</div>

I am trying to understand the fields necessary to populate custom logs into the SIEM. I have the ability to use ECS and get logs to show up, however the hosts they are coming from are not populating the "Hosts" section.…

---

## [SIEM Zeek log data getting Error decoding JSON](https://discuss.elastic.co/t/siem-zeek-log-data-getting-error-decoding-json/191103)

<div class="topic-metadata">

**Author:** [@dpangallo](https://discuss.elastic.co/u/dpangallo)\
**Replies:** 3\
**Last updated:** [July 18, 2019, 7:13pm UTC](https://discuss.elastic.co/t/siem-zeek-log-data-getting-error-decoding-json/191103 "2019-07-18T19:13:31Z")

</div>

I'm trying to ingest Zeek network log data (formerly Bro) into SIEM (Beta 7.2). Finally got it configured to ingest the data but I'm getting tons of errors decoding JSON. Here's a sample: ERROR#011readjson/json.go:52#01…

---

## [FortiAnalyzer logs to SIEM](https://discuss.elastic.co/t/fortianalyzer-logs-to-siem/190801)

<div class="topic-metadata">

**Author:** [@gabrieltavares\_pp](https://discuss.elastic.co/u/gabrieltavares_pp)\
**Replies:** 1\
**Last updated:** [July 18, 2019, 2:48pm UTC](https://discuss.elastic.co/t/fortianalyzer-logs-to-siem/190801 "2019-07-18T14:48:52Z")

</div>

Hello, I'm new with ELK and I installed Elasticsearch, Kibana and Logstash in the same server. I followed this procedure to send logs from FortiAnalyzer to ELK. I tried to send logs to SIEM, but I have to setup Beats …

---

## [Failed Logins](https://discuss.elastic.co/t/failed-logins/190118)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [July 17, 2019, 10:47pm UTC](https://discuss.elastic.co/t/failed-logins/190118 "2019-07-17T22:47:50Z")

</div>

How are failed logins tracked? I have lots of winlog.event\_id: 4771 indicating a login failure, but if I look at SIEM, it shows thousands of successful logins and 0 failed logins.

---

## [SOAR for Elastic Capabilities](https://discuss.elastic.co/t/soar-for-elastic-capabilities/190800)

<div class="topic-metadata">

**Author:** [@Joseph\_Loomis](https://discuss.elastic.co/u/Joseph_Loomis)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 4:39pm UTC](https://discuss.elastic.co/t/soar-for-elastic-capabilities/190800 "2019-07-17T16:39:58Z")

</div>

Does anyone know if Elastic is going to see more SOAR capabilities natively inside of the SIEM like Phantom and others are doing?

---

## [SIEM Elastic - Beta -7.2 - Cisco module - unable to see data](https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546)

<div class="topic-metadata">

**Author:** [@Mons](https://discuss.elastic.co/u/Mons)\
**Replies:** 2\
**Last updated:** [July 17, 2019, 1:51am UTC](https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546 "2019-07-17T01:51:58Z")

</div>

Hi All, I am trying my hands on SIEM elastic module. Wanted to configure Cisco network device’s logs using add data option under SIEM. Followed the steps under RPM. Have enabled the filebeat module for cisco as well. B…

---

## [Auditbeat file integrity monitoring does not show user who made changes to file](https://discuss.elastic.co/t/auditbeat-file-integrity-monitoring-does-not-show-user-who-made-changes-to-file/188568)

<div class="topic-metadata">

**Author:** [@EMMANUEL\_CHIBUOGWU](https://discuss.elastic.co/u/EMMANUEL_CHIBUOGWU)\
**Replies:** 4\
**Last updated:** [July 16, 2019, 8:20am UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-monitoring-does-not-show-user-who-made-changes-to-file/188568 "2019-07-16T08:20:29Z")

</div>

How can i see the user who made changes, created or deleted a file. The user who

---

## [Elastic SIEM integration with Ansible for Security Automation](https://discuss.elastic.co/t/elastic-siem-integration-with-ansible-for-security-automation/188915)

<div class="topic-metadata">

**Author:** [@imran](https://discuss.elastic.co/u/imran)\
**Replies:** 3\
**Last updated:** [July 15, 2019, 1:53pm UTC](https://discuss.elastic.co/t/elastic-siem-integration-with-ansible-for-security-automation/188915 "2019-07-15T13:53:09Z")

</div>

Hi, I wanted to know if there is a possibility where in Ansible can be integrated with the elastic SIEM app to take some automated actions against security events so that we can build a custom SOAR functionality rather …

---

## [Uncommon Processes](https://discuss.elastic.co/t/uncommon-processes/190115)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [July 15, 2019, 7:55am UTC](https://discuss.elastic.co/t/uncommon-processes/190115 "2019-07-15T07:55:06Z")

</div>

How does SIEM determine what is and is not an uncommon process?

---

## [Drilling into Suricata data](https://discuss.elastic.co/t/drilling-into-suricata-data/189629)

<div class="topic-metadata">

**Author:** [@sstover](https://discuss.elastic.co/u/sstover)\
**Replies:** 4\
**Last updated:** [July 11, 2019, 6:46pm UTC](https://discuss.elastic.co/t/drilling-into-suricata-data/189629 "2019-07-11T18:46:31Z")

</div>

We're a Suricata shop and I was hoping to use the SIEM to crossreference things like (external) IP reputation with Suricata events using the SIEM. Starting out slowly, before jumping into anything like external reputati…

---

## [Last Seen timestamp under Hosts section appears to be incorrect](https://discuss.elastic.co/t/last-seen-timestamp-under-hosts-section-appears-to-be-incorrect/189769)

<div class="topic-metadata">

**Author:** [@redrise](https://discuss.elastic.co/u/redrise)\
**Replies:** 2\
**Last updated:** [July 11, 2019, 7:06am UTC](https://discuss.elastic.co/t/last-seen-timestamp-under-hosts-section-appears-to-be-incorrect/189769 "2019-07-11T07:06:31Z")

</div>

I've just been trying the new SIEM stuff out and i fired a load of data in from auditbeat, filebeat, and packetbeat on a CentOS 7 box. When I looked at the Hosts section in the SIEM part of Kibana I noticed the value fo…

---

## [Trouble with Index Patterns](https://discuss.elastic.co/t/trouble-with-index-patterns/188981)

<div class="topic-metadata">

**Author:** [@mindorod](https://discuss.elastic.co/u/mindorod)\
**Replies:** 12\
**Last updated:** [July 5, 2019, 2:33pm UTC](https://discuss.elastic.co/t/trouble-with-index-patterns/188981 "2019-07-05T14:33:01Z")

</div>

Hi - Having a bit of trouble with the SIEM + beats configuration regarding index mappings. I've stood up 7.2 with the latest beats and followed the documentation to the T. When I open the SIEM app, I can see most of my d…

---

## [Configuring SIEM](https://discuss.elastic.co/t/configuring-siem/187793)

<div class="topic-metadata">

**Author:** [@clem1](https://discuss.elastic.co/u/clem1)\
**Replies:** 2\
**Last updated:** [July 5, 2019, 11:15am UTC](https://discuss.elastic.co/t/configuring-siem/187793 "2019-07-05T11:15:00Z")

</div>

Hello all, I have been playing with ELK for a month now, and I want to setup alerting rules based on failed attempts or so. For now, I have only found ElastAlert on github. Recently, I heard that there is a new functio…

---

## [Netflow data ingested but not showing under SIEM | Network](https://discuss.elastic.co/t/netflow-data-ingested-but-not-showing-under-siem-network/188897)

<div class="topic-metadata">

**Author:** [@involuntary-pretzel](https://discuss.elastic.co/u/involuntary-pretzel)\
**Replies:** 2\
**Last updated:** [July 4, 2019, 12:30pm UTC](https://discuss.elastic.co/t/netflow-data-ingested-but-not-showing-under-siem-network/188897 "2019-07-04T12:30:35Z")

</div>

Hi I have a fresh install of logstash 7.2 with netflow configure following the /home/tutorial/netflow tutorial, and its pushing data to elastic.cloud (7.2) sucessfully. The Dashboard Netflow: Overview work great and no …

---

## [Role to provide access to SIEM?](https://discuss.elastic.co/t/role-to-provide-access-to-siem/188629)

<div class="topic-metadata">

**Author:** [@kmohd](https://discuss.elastic.co/u/kmohd)\
**Replies:** 2\
**Last updated:** [July 4, 2019, 4:11am UTC](https://discuss.elastic.co/t/role-to-provide-access-to-siem/188629 "2019-07-04T04:11:49Z")

</div>

Is there any role to provide read only access to SIEM? Its working for superusers however i cannot find a specific role just for that.

---

## [SIEM not ingesting Windows logs from servers](https://discuss.elastic.co/t/siem-not-ingesting-windows-logs-from-servers/188653)

<div class="topic-metadata">

**Author:** [@sc1](https://discuss.elastic.co/u/sc1)\
**Replies:** 7\
**Last updated:** [July 3, 2019, 1:48pm UTC](https://discuss.elastic.co/t/siem-not-ingesting-windows-logs-from-servers/188653 "2019-07-03T13:48:36Z")

</div>

Hello, I've been testing the new SIEM function, I've got 2 domain controllers/servers sending through logs via Winlogbeat and 4 client PCs sending logs again through the same method. When I check via dashboards or even …

---

## [Inserting Logs into SIEM](https://discuss.elastic.co/t/inserting-logs-into-siem/188510)

<div class="topic-metadata">

**Author:** [@inteli](https://discuss.elastic.co/u/inteli)\
**Replies:** 2\
**Last updated:** [July 3, 2019, 11:17am UTC](https://discuss.elastic.co/t/inserting-logs-into-siem/188510 "2019-07-03T11:17:14Z")

</div>

Hi Guys, the new elastic SIEM timeline feature looks amazing and I would like to use it for log analysis. Unfortunately I don't have that much experience regarding ELK setup. If i understand correctly it is only possi…

---

## [SIEM Parsing](https://discuss.elastic.co/t/siem-parsing/188291)

<div class="topic-metadata">

**Author:** [@pinguin](https://discuss.elastic.co/u/pinguin)\
**Replies:** 1\
**Last updated:** [July 1, 2019, 9:34pm UTC](https://discuss.elastic.co/t/siem-parsing/188291 "2019-07-01T21:34:28Z")

</div>

we are trying to send windows event logs using winlogbeat 7.XX version , we are creating severals of dashboards based on the correlation rules of event built on top of event ,sysmon and security logs ex : event.id =1 AND…

---

## [Host.hostname field bug](https://discuss.elastic.co/t/host-hostname-field-bug/188219)

<div class="topic-metadata">

**Author:** [@Chinedum\_Nwuzor](https://discuss.elastic.co/u/Chinedum_Nwuzor)\
**Replies:** 6\
**Last updated:** [July 1, 2019, 3:55pm UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219 "2019-07-01T15:55:44Z")

</div>

Can anyone please help resolve this?

---

## [Lists](https://discuss.elastic.co/t/lists/188163)

<div class="topic-metadata">

**Author:** [@anon15412260](https://discuss.elastic.co/u/anon15412260)\
**Replies:** 1\
**Last updated:** [July 1, 2019, 10:30am UTC](https://discuss.elastic.co/t/lists/188163 "2019-07-01T10:30:19Z")

</div>

Would be neat if this SIEM module allowed for users to build out lists to add/remove/modify entries so easily query and alert on items. For instance when searching, users could add users/ips/urls to a known bad list for …

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=23)
