# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=3

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 4

---

## [Log Stoppage Monitoring](https://discuss.elastic.co/t/log-stoppage-monitoring/358407)

<div class="topic-metadata">

**Author:** [@Phoenix1](https://discuss.elastic.co/u/Phoenix1)\
**Replies:** 0\
**Last updated:** [April 29, 2024, 9:15am UTC](https://discuss.elastic.co/t/log-stoppage-monitoring/358407 "2024-04-29T09:15:31Z")

</div>

How to create Log stoppage alert in Elasitc SIEM for any logsource/Index ?

---

## [Create Detection Rules via TF](https://discuss.elastic.co/t/create-detection-rules-via-tf/358040)

<div class="topic-metadata">

**Author:** [@Sunil\_Iyengar](https://discuss.elastic.co/u/Sunil_Iyengar)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 3:11pm UTC](https://discuss.elastic.co/t/create-detection-rules-via-tf/358040 "2024-04-23T15:11:42Z")

</div>

Are there any examples of enabling and applying the default detection rules via terraform? Regards Sunil

---

## [System Virtual Process Detection Rule](https://discuss.elastic.co/t/system-virtual-process-detection-rule/356401)

<div class="topic-metadata">

**Author:** [@Brandon\_Duffy](https://discuss.elastic.co/u/Brandon_Duffy)\
**Replies:** 1\
**Last updated:** [April 19, 2024, 3:33pm UTC](https://discuss.elastic.co/t/system-virtual-process-detection-rule/356401 "2024-04-19T15:33:42Z")

</div>

Had a question about the rule "Unusual Child Process from a System Virtual Process", sorry if this is not the correct forum for it. I'm using the most recent rule query and when these alerts do spawn, we are unable to te…

---

## [Fleet Deploy OSQuery to Windows](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 3\
**Last updated:** [April 17, 2024, 1:24pm UTC](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301 "2024-04-17T13:24:35Z")

</div>

I have successfully deployed both OSQuery manager and one agent to a Linux machine. However; my deployment to a Windows box doesn't seem to be working. I believe it's because the log path needs to be modified to someth…

---

## [Sending the alert JSON details using Webhook Connector](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223)

<div class="topic-metadata">

**Author:** [@aviran-cato](https://discuss.elastic.co/u/aviran-cato)\
**Replies:** 7\
**Last updated:** [April 11, 2024, 3:42pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223 "2024-04-11T15:42:06Z")

</div>

Hi, I want to use a Webhook connector to send the alert data to an automation platform. The issue is that in the Connector action, I can't find a way to send only the JSON alert information. As marked in the image. …

---

## [Notification from machine learning job per anomaly score](https://discuss.elastic.co/t/notification-from-machine-learning-job-per-anomaly-score/357148)

<div class="topic-metadata">

**Author:** [@Poukim0m](https://discuss.elastic.co/u/Poukim0m)\
**Replies:** 0\
**Last updated:** [April 10, 2024, 1:02pm UTC](https://discuss.elastic.co/t/notification-from-machine-learning-job-per-anomaly-score/357148 "2024-04-10T13:02:36Z")

</div>

Can I setup a notification mail at the level of a machine learning job depending on the anomaly score? For example I want to get notified when anomaly score \>=80 Thank you, Vivian

---

## [How do I adding Suricata events to Elasticsearch](https://discuss.elastic.co/t/how-do-i-adding-suricata-events-to-elasticsearch/356827)

<div class="topic-metadata">

**Author:** [@rayobe4014](https://discuss.elastic.co/u/rayobe4014)\
**Replies:** 7\
**Last updated:** [April 9, 2024, 5:26am UTC](https://discuss.elastic.co/t/how-do-i-adding-suricata-events-to-elasticsearch/356827 "2024-04-09T05:26:56Z")

</div>

I just configuration Exebox with Elasticsearch and Suricata but Elasticsearch not get event from Suricata so how can I add Suricata event to Elasticsearch ? Please guide me how to add Suricata event to Elasticsearch. …

---

## [Elastic pricing for on-premises deployment](https://discuss.elastic.co/t/elastic-pricing-for-on-premises-deployment/356980)

<div class="topic-metadata">

**Author:** [@S\_n\_Ngo\_Hoang](https://discuss.elastic.co/u/S_n_Ngo_Hoang)\
**Replies:** 5\
**Last updated:** [April 8, 2024, 4:26pm UTC](https://discuss.elastic.co/t/elastic-pricing-for-on-premises-deployment/356980 "2024-04-08T16:26:21Z")

</div>

Hello, I am currently working as a security analyst and am interested in Elastic and Machine Learning solutions. Currently I want to deploy Elastic Stack on-premises with 3 Elasticsearch nodes and 2 nodes for ML. I tried…

---

## [Elastic Stack for SIEM(Elastic Security)](https://discuss.elastic.co/t/elastic-stack-for-siem-elastic-security/356870)

<div class="topic-metadata">

**Author:** [@Aliya\_Khalel](https://discuss.elastic.co/u/Aliya_Khalel)\
**Replies:** 1\
**Last updated:** [April 5, 2024, 2:19pm UTC](https://discuss.elastic.co/t/elastic-stack-for-siem-elastic-security/356870 "2024-04-05T14:19:42Z")

</div>

Hello, I am noob in Elastic. We planning to use Elastic Security for MSSP. 3 nodes of Elastic will be in private datacenter and our customer's logs will send by VPN. The question: I don't know how to forward data from…

---

## [Elastic Agent - Ship Windows logs for SIEM](https://discuss.elastic.co/t/elastic-agent-ship-windows-logs-for-siem/356751)

<div class="topic-metadata">

**Author:** [@The\_BlueishSky](https://discuss.elastic.co/u/The_BlueishSky)\
**Replies:** 0\
**Last updated:** [April 4, 2024, 9:03am UTC](https://discuss.elastic.co/t/elastic-agent-ship-windows-logs-for-siem/356751 "2024-04-04T09:03:05Z")

</div>

We are in the process of deploying ELASTIC AGENT on all CLIENT OS , We intend to capture Windows Event logs more focused on Security Events which would be used for our SIEM. Any standard filters that can be applied and e…

---

## [Elastic Search not work with evebox](https://discuss.elastic.co/t/elastic-search-not-work-with-evebox/355353)

<div class="topic-metadata">

**Author:** [@jed](https://discuss.elastic.co/u/jed)\
**Replies:** 5\
**Last updated:** [March 14, 2024, 3:47am UTC](https://discuss.elastic.co/t/elastic-search-not-work-with-evebox/355353 "2024-03-14T03:47:17Z")

</div>

I just create Elastic on Debain server and and connect with Evebox to get logs from suricata but it not work. here is my configuration Elasticsearch # Use a descriptive name for your cluster: # cluster.name: suricata # …

---

## [Webhook - Case Management connector JSON payload from case object variables](https://discuss.elastic.co/t/webhook-case-management-connector-json-payload-from-case-object-variables/355060)

<div class="topic-metadata">

**Author:** [@aperez900907](https://discuss.elastic.co/u/aperez900907)\
**Replies:** 0\
**Last updated:** [March 8, 2024, 6:51pm UTC](https://discuss.elastic.co/t/webhook-case-management-connector-json-payload-from-case-object-variables/355060 "2024-03-08T18:51:16Z")

</div>

Is it possible to pass a richer context to an External incident management system by object variables? currently, the documentation only explains the following: { "fields": { "summary": {{{case.title}}}, "descri…

---

## [Orchestrate Elastic SIEM for training labs](https://discuss.elastic.co/t/orchestrate-elastic-siem-for-training-labs/353607)

<div class="topic-metadata">

**Author:** [@lastshadow](https://discuss.elastic.co/u/lastshadow)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 6:22pm UTC](https://discuss.elastic.co/t/orchestrate-elastic-siem-for-training-labs/353607 "2024-02-28T18:22:28Z")

</div>

I have a cybersecurity training program that I teach. Currently I teach it live and I use Elastic SIEM. I think it is a great product and not just because of the cost. I deploy Elastic on docker and have it running for t…

---

## [Shiiping audit logs for DB with no connector available in Integrations](https://discuss.elastic.co/t/shiiping-audit-logs-for-db-with-no-connector-available-in-integrations/354232)

<div class="topic-metadata">

**Author:** [@Nouman\_Ahmed](https://discuss.elastic.co/u/Nouman_Ahmed)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 2:58pm UTC](https://discuss.elastic.co/t/shiiping-audit-logs-for-db-with-no-connector-available-in-integrations/354232 "2024-02-28T14:58:53Z")

</div>

I have question why there are no connectors available for DBs like mongoDB, SQLite etc to capture audit logs while they are availble for SQL server, mysql?? and if there is no connector avaible to capture audit logs of m…

---

## [Correlation Query for spam email - not working](https://discuss.elastic.co/t/correlation-query-for-spam-email-not-working/354175)

<div class="topic-metadata">

**Author:** [@hamidijaz](https://discuss.elastic.co/u/hamidijaz)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 4:55am UTC](https://discuss.elastic.co/t/correlation-query-for-spam-email-not-working/354175 "2024-02-27T04:55:55Z")

</div>

Hi, I have created a correlation rule with the following query, that runs every 5 mins. This is to detect if any external email address sends multiple emails to our internal email within given time (an hour), then it sh…

---

## [Modify ID of an installed agent](https://discuss.elastic.co/t/modify-id-of-an-installed-agent/353991)

<div class="topic-metadata">

**Author:** [@Amanda\_Riverol\_Quesa](https://discuss.elastic.co/u/Amanda_Riverol_Quesa)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 3:02pm UTC](https://discuss.elastic.co/t/modify-id-of-an-installed-agent/353991 "2024-02-23T15:02:29Z")

</div>

\*Good afternoon! I wanted to know if it is possible to change the ID of an agent once installed, the problem it would be presenting is that when cloning a VM the agent remains installed and with the ID the base machine,…

---

## [File Integrity Monitor Missing Events](https://discuss.elastic.co/t/file-integrity-monitor-missing-events/352141)

<div class="topic-metadata">

**Author:** [@wrsnrno](https://discuss.elastic.co/u/wrsnrno)\
**Replies:** 2\
**Last updated:** [February 3, 2024, 12:40pm UTC](https://discuss.elastic.co/t/file-integrity-monitor-missing-events/352141 "2024-02-03T12:40:19Z")

</div>

File Integrity Monitor missed several events in a recent planned software deployment. FIM is configured to track the application folder on a dozen nearly identical hosts and was first initialized about a month ago. Oth…

---

## [Elastic SIEM](https://discuss.elastic.co/t/elastic-siem/350026)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 2:54pm UTC](https://discuss.elastic.co/t/elastic-siem/350026 "2023-12-27T14:54:06Z")

</div>

Hello All, I hope all is well with you. I'm new to elastic and I want to inquire if we can fully depend on elastic security as siem solution? Thnk you in advance.

---

## [Determine the user that acknowledged an Alert](https://discuss.elastic.co/t/determine-the-user-that-acknowledged-an-alert/349426)

<div class="topic-metadata">

**Author:** [@lastshadow](https://discuss.elastic.co/u/lastshadow)\
**Replies:** 5\
**Last updated:** [December 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/determine-the-user-that-acknowledged-an-alert/349426 "2023-12-21T16:21:32Z")

</div>

I have several SOC analysts in my SIEM and need to figure out the following: How do I determine who acknowledged an alert? How can the analysts filter their acknowledged alerts so they only see what they have acknowled…

---

## [Rules failing](https://discuss.elastic.co/t/rules-failing/349470)

<div class="topic-metadata">

**Author:** [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 7:25pm UTC](https://discuss.elastic.co/t/rules-failing/349470 "2023-12-18T19:25:17Z")

</div>

Hi, I have several rules that come back as Failed after running. I'm getting the following error for many rules. The field names for the unknown column message varies among the different rules. An error occurred during…

---

## [ServiceNow SecOps connector](https://discuss.elastic.co/t/servicenow-secops-connector/348374)

<div class="topic-metadata">

**Author:** [@John\_McAfee1](https://discuss.elastic.co/u/John_McAfee1)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 10:20pm UTC](https://discuss.elastic.co/t/servicenow-secops-connector/348374 "2023-11-30T22:20:09Z")

</div>

Hello, I am testing the SecOps service now connector on my Personal Development Instance provided by serive now. I have followed the instructions outlined in the documentation: ServiceNow SecOps connector and action | …

---

## [Indicator Detection](https://discuss.elastic.co/t/indicator-detection/347862)

<div class="topic-metadata">

**Author:** [@Phoenix1](https://discuss.elastic.co/u/Phoenix1)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 4:49pm UTC](https://discuss.elastic.co/t/indicator-detection/347862 "2023-11-28T16:49:55Z")

</div>

I want to use a CSV(Indicator file) lookup to detect the indicators available in the file to report an alert. please suggest.

---

## [Elastic Security - what is the difference between adding something to the fleet, and a host / endpoint?](https://discuss.elastic.co/t/elastic-security-what-is-the-difference-between-adding-something-to-the-fleet-and-a-host-endpoint/348086)

<div class="topic-metadata">

**Author:** [@jordan\_pritchard](https://discuss.elastic.co/u/jordan_pritchard)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 8:56pm UTC](https://discuss.elastic.co/t/elastic-security-what-is-the-difference-between-adding-something-to-the-fleet-and-a-host-endpoint/348086 "2023-11-27T20:56:11Z")

</div>

Hi - I've been testing deploying Elastic Agent. The agent installs without error and I see the agent show up in the fleet, but on roughly half the servers I am testing on, I don't see them show up in Hosts or Endpoints. …

---

## [Google Workspace integration - logs-sdk admin](https://discuss.elastic.co/t/google-workspace-integration-logs-sdk-admin/347257)

<div class="topic-metadata">

**Author:** [@Eldr](https://discuss.elastic.co/u/Eldr)\
**Replies:** 1\
**Last updated:** [November 16, 2023, 12:23pm UTC](https://discuss.elastic.co/t/google-workspace-integration-logs-sdk-admin/347257 "2023-11-16T12:23:29Z")

</div>

I get this error despite following Elastic's documentation to the letter. this is the error (No authentication credentials were configured or detectec (ADC) accesing 'auth.oauth2') Also, I don't understand what this…

---

## [How to integrate SCIM Server (Basic Auth) with SailPoint IIQ?](https://discuss.elastic.co/t/how-to-integrate-scim-server-basic-auth-with-sailpoint-iiq/347185)

<div class="topic-metadata">

**Author:** [@srikanth\_bollu](https://discuss.elastic.co/u/srikanth_bollu)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 4:15am UTC](https://discuss.elastic.co/t/how-to-integrate-scim-server-basic-auth-with-sailpoint-iiq/347185 "2023-11-15T04:15:43Z")

</div>

I am running Okta's Example SCIM (v2.0) Server and I wish to know how to integrate it with SailPoint IIQ. It asks for the Basic Authentication username and password. However, the example app has not authentication config…

---

## [Detection rules: include Kibana visualization in email](https://discuss.elastic.co/t/detection-rules-include-kibana-visualization-in-email/347159)

<div class="topic-metadata">

**Author:** [@cdelgado](https://discuss.elastic.co/u/cdelgado)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 7:20pm UTC](https://discuss.elastic.co/t/detection-rules-include-kibana-visualization-in-email/347159 "2023-11-14T19:20:52Z")

</div>

Hi all, Is there any way to include Kibana visualizations (i.e., from Visualize Library) in the Email action of a Detection Rule? I am looking for different available options to include more complex forms of data on a …

---

## [Detection rule: Email CSV file as action](https://discuss.elastic.co/t/detection-rule-email-csv-file-as-action/347065)

<div class="topic-metadata">

**Author:** [@cdelgado](https://discuss.elastic.co/u/cdelgado)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 10:12pm UTC](https://discuss.elastic.co/t/detection-rule-email-csv-file-as-action/347065 "2023-11-13T22:12:19Z")

</div>

Hello, When configuring Detection Rules, is there a way to send a CSV file as part of the Email action (when the rule triggers)? I am aware Mustache and Markdown syntax is supported for the email body, but I was wonderi…

---

## [Detection alerts not visible to all users](https://discuss.elastic.co/t/detection-alerts-not-visible-to-all-users/346456)

<div class="topic-metadata">

**Author:** [@abubacker](https://discuss.elastic.co/u/abubacker)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 8:57am UTC](https://discuss.elastic.co/t/detection-alerts-not-visible-to-all-users/346456 "2023-11-13T08:57:57Z")

</div>

Hi All, Elastic detection alerts are not visible to all users and are highlighted in yellow. All other alerts are visible some alerts only have this issue. If anyone knows how to solve this issue please let me know w…

---

## [Where are Security Rules run?](https://discuss.elastic.co/t/where-are-security-rules-run/346753)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 4\
**Last updated:** [November 10, 2023, 12:43pm UTC](https://discuss.elastic.co/t/where-are-security-rules-run/346753 "2023-11-10T12:43:39Z")

</div>

The security rules and alerts are fantastic in ELK. Am curious to know, where are the Rules (which dont require Machine Learning) run from? Is it the instance running Kibana or one of the Elastic instances with a speci…

---

## [Aggregate alerts by a specific field and send a summary through an action for each field value encountered](https://discuss.elastic.co/t/aggregate-alerts-by-a-specific-field-and-send-a-summary-through-an-action-for-each-field-value-encountered/346698)

<div class="topic-metadata">

**Author:** [@Arty](https://discuss.elastic.co/u/Arty)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 10:52am UTC](https://discuss.elastic.co/t/aggregate-alerts-by-a-specific-field-and-send-a-summary-through-an-action-for-each-field-value-encountered/346698 "2023-11-08T10:52:37Z")

</div>

Hi everyone, I have set up a Kibana alert security detection rule which creates an alert for all my incoming third-party system alerts (Suricata) and send each one of them to my SIRP using webhook. I have many alerts w…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=2)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=4)
