# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=4

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 5

---

## [Configure Fleet SSL Cert Port 8220](https://discuss.elastic.co/t/configure-fleet-ssl-cert-port-8220/346157)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 12:49pm UTC](https://discuss.elastic.co/t/configure-fleet-ssl-cert-port-8220/346157 "2023-11-01T12:49:36Z")

</div>

I have deployed a Fleet server and I want to change the SSL cert that is being used. Is there a config file somewhere that I can modify to use the certificates that I generated? I want to avoid having to use the --inse…

---

## [Notes on Alerts or auto open case](https://discuss.elastic.co/t/notes-on-alerts-or-auto-open-case/345771)

<div class="topic-metadata">

**Author:** [@Renato\_Arraes](https://discuss.elastic.co/u/Renato_Arraes)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 5:41am UTC](https://discuss.elastic.co/t/notes-on-alerts-or-auto-open-case/345771 "2023-10-26T05:41:51Z")

</div>

Hello everyone, Im currently doing the configuration of the Alerts, and i want to know if theres a way to put some notes or open directly a case from an alert, since we do have to treat the Alerts we need to input some …

---

## [Problem with security timelines for alias](https://discuss.elastic.co/t/problem-with-security-timelines-for-alias/343966)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:34am UTC](https://discuss.elastic.co/t/problem-with-security-timelines-for-alias/343966 "2023-09-27T09:34:04Z")

</div>

Hello! I use alias for aggregate and display log log from different sources and I often use alias for SIEM rules and it is work great. But I can't use alias for timeline. When I choose alias in timeline I can't choos…

---

## [EQL sequence detection on windows and cloudtrail](https://discuss.elastic.co/t/eql-sequence-detection-on-windows-and-cloudtrail/345383)

<div class="topic-metadata">

**Author:** [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 11:36am UTC](https://discuss.elastic.co/t/eql-sequence-detection-on-windows-and-cloudtrail/345383 "2023-10-19T11:36:33Z")

</div>

Hi all,I have a bit of a challenge in building a detection, hoping someone has a good idea. scenario We have a couple of windows hosts in a dedicated aws account which should only be turned on temporary. I am looking t…

---

## [Turn on Anonymous access](https://discuss.elastic.co/t/turn-on-anonymous-access/343822)

<div class="topic-metadata">

**Author:** [@gabrielpicagevicz](https://discuss.elastic.co/u/gabrielpicagevicz)\
**Replies:** 4\
**Last updated:** [October 3, 2023, 12:19am UTC](https://discuss.elastic.co/t/turn-on-anonymous-access/343822 "2023-10-03T00:19:46Z")

</div>

I currently have version 8.9.1 of Kibana (basic license) installed on my machine. I created an anonymous user with full access to testing I've added the following to Elasticsearch.yml xpack.security.authc: anonymous:…

---

## [Aggregate Logs based on Source IP](https://discuss.elastic.co/t/aggregate-logs-based-on-source-ip/343789)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 4:16pm UTC](https://discuss.elastic.co/t/aggregate-logs-based-on-source-ip/343789 "2023-09-25T16:16:26Z")

</div>

Hello, I'm collecting firewall logs from a firewall (PfSense). On every log record, among other details, I have destination ip addresses and destination ports. Now, I need to have an aggregated list of all destination…

---

## [Filter Alerts by data\_stream.namespace](https://discuss.elastic.co/t/filter-alerts-by-data-stream-namespace/343517)

<div class="topic-metadata">

**Author:** [@DVCS](https://discuss.elastic.co/u/DVCS)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 8:56am UTC](https://discuss.elastic.co/t/filter-alerts-by-data-stream-namespace/343517 "2023-09-21T08:56:57Z")

</div>

Hi All, I'm trying to filter alerts with KQL using "data\_stream.namespace" in Security -\> Alerts but no results. Even using "Group alerts by" with "data\_stream.namespace" gives no result. But the field is visible and …

---

## [The issue in a detection rule](https://discuss.elastic.co/t/the-issue-in-a-detection-rule/343448)

<div class="topic-metadata">

**Author:** [@saudmajed99](https://discuss.elastic.co/u/saudmajed99)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 2:14pm UTC](https://discuss.elastic.co/t/the-issue-in-a-detection-rule/343448 "2023-09-20T14:14:08Z")

</div>

Hi there, We would like your support, we face an issue if we create a detection rule where no result appears but results appears when we do the same search in the discover side , please assist me the solving an issue wi…

---

## [Multi-value lists for elk rule](https://discuss.elastic.co/t/multi-value-lists-for-elk-rule/342579)

<div class="topic-metadata">

**Author:** [@Poukim0m](https://discuss.elastic.co/u/Poukim0m)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 7:16am UTC](https://discuss.elastic.co/t/multi-value-lists-for-elk-rule/342579 "2023-09-08T07:16:27Z")

</div>

Do you know how to implement the functionality of lists (for the purpose of exclusion/whitelisting) that contain multiple (two or more) fields (values) in each entry? For example i need to have a list with the combinati…

---

## [Can i configure Mikrotik Router in Elastic ELK?](https://discuss.elastic.co/t/can-i-configure-mikrotik-router-in-elastic-elk/341227)

<div class="topic-metadata">

**Author:** [@Heetav](https://discuss.elastic.co/u/Heetav)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 11:01am UTC](https://discuss.elastic.co/t/can-i-configure-mikrotik-router-in-elastic-elk/341227 "2023-08-21T11:01:06Z")

</div>

Hi, We are using Elastic ELK with Kibana version. If there any way that I can configure Mikrotik Router in SIEM/SOC operations ?

---

## [Threshold detection rule - limitation of group by fields](https://discuss.elastic.co/t/threshold-detection-rule-limitation-of-group-by-fields/338383)

<div class="topic-metadata">

**Author:** [@Poukim0m](https://discuss.elastic.co/u/Poukim0m)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/threshold-detection-rule-limitation-of-group-by-fields/338383 "2023-08-22T13:51:54Z")

</div>

Hello, I want to implement a threshold detection rule that aggregates more than 3 fields in the "Group by" section of rule definition. But there seems to be a limitation of 3 fields as i get an error message "Number of …

---

## [Create a rule or alert to monitor when its not receiving logs by 24 hours?](https://discuss.elastic.co/t/create-a-rule-or-alert-to-monitor-when-its-not-receiving-logs-by-24-hours/340932)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 5:00pm UTC](https://discuss.elastic.co/t/create-a-rule-or-alert-to-monitor-when-its-not-receiving-logs-by-24-hours/340932 "2023-08-21T17:00:37Z")

</div>

Hi, I've been trying to check how to create this type of rule in the forum and I saw that other people have the same problem

---

## [Registering Wasabi as Snapshot repository for ECE cluster](https://discuss.elastic.co/t/registering-wasabi-as-snapshot-repository-for-ece-cluster/339297)

<div class="topic-metadata">

**Author:** [@kkumari](https://discuss.elastic.co/u/kkumari)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 3:47pm UTC](https://discuss.elastic.co/t/registering-wasabi-as-snapshot-repository-for-ece-cluster/339297 "2023-08-14T15:47:04Z")

</div>

How do I register Wasabi as Snapshot repository for my ECE cluster?

---

## [Decentralised architecture with elastic SIEM](https://discuss.elastic.co/t/decentralised-architecture-with-elastic-siem/340598)

<div class="topic-metadata">

**Author:** [@kafikone](https://discuss.elastic.co/u/kafikone)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 2:15am UTC](https://discuss.elastic.co/t/decentralised-architecture-with-elastic-siem/340598 "2023-08-11T02:15:07Z")

</div>

Hi all I have a concern and I would like to have some leads if possible. I'd like to know if it's possible for elastic agents installed on machines at a company site in town A, for example, to be able to send logs to t…

---

## [EQL query to alert 1 alert per each user](https://discuss.elastic.co/t/eql-query-to-alert-1-alert-per-each-user/339539)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 1:15pm UTC](https://discuss.elastic.co/t/eql-query-to-alert-1-alert-per-each-user/339539 "2023-08-08T13:15:08Z")

</div>

Hello all! I'd like to create a Rule based on the EQL query that will trigger an alert only once per user. For example: The input list of logs is user1 ip1 user1 ip1 user2 ip2 user5 ip5 user4 ip4 user4 ip4 user…

---

## [How to do to show field values in Kibana alert?](https://discuss.elastic.co/t/how-to-do-to-show-field-values-in-kibana-alert/340319)

<div class="topic-metadata">

**Author:** [@aungsoemin](https://discuss.elastic.co/u/aungsoemin)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:12am UTC](https://discuss.elastic.co/t/how-to-do-to-show-field-values-in-kibana-alert/340319 "2023-08-08T04:12:38Z")

</div>

Hi Everyone, I created the custom rule to get the alert when there is successful login from public IP for Windows host. The lucene query is as per below. (winlog.channel:Security AND winlog.event\_id:4624 AND (NOT ((win…

---

## [Inserting Custom Logs Into Siem](https://discuss.elastic.co/t/inserting-custom-logs-into-siem/340092)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 3:35am UTC](https://discuss.elastic.co/t/inserting-custom-logs-into-siem/340092 "2023-08-04T03:35:16Z")

</div>

Hi @cwurm, Referring to this topic - Inserting Custom Logs Into Siem I am using Custom Log Integration, using everything as default , I only added custom pattern for below logs. 2023-07-25T08:05:25.661Z ERRO 1 --- \[…

---

## [Elastic Security - Host No longer logging Alert](https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043)

<div class="topic-metadata">

**Author:** [@g.spasov](https://discuss.elastic.co/u/g.spasov)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 12:22pm UTC](https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043 "2023-08-03T12:22:58Z")

</div>

Hello, I want to create a detection rule in Elastic Security that would trigger when no logs have been injested to Elastic for more than 24 hours from a particular host.name. The idea is to detect potential logging pro…

---

## [Alert when winlogbeat host stop sending events](https://discuss.elastic.co/t/alert-when-winlogbeat-host-stop-sending-events/339141)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 2:47pm UTC](https://discuss.elastic.co/t/alert-when-winlogbeat-host-stop-sending-events/339141 "2023-07-25T14:47:04Z")

</div>

Hello and thanks in advance. I have a group of 100+ hosts with winlogbeat installed and sending events to elasticsearch cluster. Is there any options to generate an alert (on security or any other page) when one or gro…

---

## [Soar in elastic](https://discuss.elastic.co/t/soar-in-elastic/334425)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 5:25pm UTC](https://discuss.elastic.co/t/soar-in-elastic/334425 "2023-06-27T17:25:21Z")

</div>

I understand there is a way to create a case and assign to someone when an alert is triggered. But SOAR means automatic remediation. The documentation says 'Easily automate your team’s security incident response with Ela…

---

## [Preventing/identifying credit card breach in elastic using SIEM](https://discuss.elastic.co/t/preventing-identifying-credit-card-breach-in-elastic-using-siem/337014)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:45pm UTC](https://discuss.elastic.co/t/preventing-identifying-credit-card-breach-in-elastic-using-siem/337014 "2023-06-27T15:45:09Z")

</div>

Hi! I see elastic has a rich array of security features (SIEM, security analytics, endpoint detection, etc). Is there a way to identify/detect if credit card details were crawled by hackers for online transactions? Gi…

---

## [Threshold rule](https://discuss.elastic.co/t/threshold-rule/336528)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 4:19am UTC](https://discuss.elastic.co/t/threshold-rule/336528 "2023-06-22T04:19:27Z")

</div>

Hello everyone I would like to clarify. For example, I am trying to add threshold rule against login failed attempt If user failes more than 4 times, I should get an alert From the picture above, I am grouping by …

---

## [Rules and connectors](https://discuss.elastic.co/t/rules-and-connectors/336531)

<div class="topic-metadata">

**Author:** [@imaad](https://discuss.elastic.co/u/imaad)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 6:01am UTC](https://discuss.elastic.co/t/rules-and-connectors/336531 "2023-06-21T06:01:56Z")

</div>

Hello, I want to create an Alert to monitor a specific pattern error every 4 hours which occurs in the message field. Could not connect to net.tcp: The connection attempt lasted for a time span of TCP error code 10061…

---

## [\[Agent-Netflow\] Anomaly Detect for spikes on coms between 2 IP](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542)

<div class="topic-metadata">

**Author:** [@isaqueprofeta](https://discuss.elastic.co/u/isaqueprofeta)\
**Replies:** 5\
**Last updated:** [June 13, 2023, 9:49pm UTC](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542 "2023-06-13T21:49:52Z")

</div>

Hey everyone, thanks for having me, I'm currently working with Elastic 8.3 using an Agent (Fleet managed) with Netflow Integration. My current goal is to create two ML Jobs for spikes on traffic between 2 IP's, but I …

---

## [Normalizing the Huawei firewall logs](https://discuss.elastic.co/t/normalizing-the-huawei-firewall-logs/335861)

<div class="topic-metadata">

**Author:** [@Imad\_TAMELGHAGHET](https://discuss.elastic.co/u/Imad_TAMELGHAGHET)\
**Replies:** 4\
**Last updated:** [June 13, 2023, 3:07pm UTC](https://discuss.elastic.co/t/normalizing-the-huawei-firewall-logs/335861 "2023-06-13T15:07:58Z")

</div>

Hello , I am actually working on a ELK SIEM project, and one of the logs sources i am woking with is a Huawei Firewall .Since Huawei firewall logs have differents formats, I would appreciate some suggestions and insight…

---

## [Bulk Indexing of signals failed: object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete value name](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-name/334705)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 3:53pm UTC](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-name/334705 "2023-06-02T15:53:18Z")

</div>

Hi team, the parser used for Kaspersky, more precisely in the host field, does not allow the triggering of the rule relating to the detection of malicious files once the conditions are met.

---

## [MISP + Alerts](https://discuss.elastic.co/t/misp-alerts/334280)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 7\
**Last updated:** [May 31, 2023, 6:37pm UTC](https://discuss.elastic.co/t/misp-alerts/334280 "2023-05-31T18:37:03Z")

</div>

I had connect MISP to ELK with filebeat. So now i have index named filebeat, there are many IOCs. Next i have index with network activity from workstations. So i want to match IP from winlog index with IOCs from MISP …

---

## [How to check if Application run as administrator](https://discuss.elastic.co/t/how-to-check-if-application-run-as-administrator/333514)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 1:47am UTC](https://discuss.elastic.co/t/how-to-check-if-application-run-as-administrator/333514 "2023-05-26T01:47:14Z")

</div>

Hello i have a question Is there any rules to detect if any application run as administrator or if a user run the application as admin in windows machine ?

---

## [Assign current user to acknowledged alert / Elastic Security](https://discuss.elastic.co/t/assign-current-user-to-acknowledged-alert-elastic-security/334314)

<div class="topic-metadata">

**Author:** [@Mike\_S](https://discuss.elastic.co/u/Mike_S)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:46am UTC](https://discuss.elastic.co/t/assign-current-user-to-acknowledged-alert-elastic-security/334314 "2023-05-25T11:46:16Z")

</div>

Hi, Is it possible to set the current user that has acknowledged an alert to a new field using the painless / runtime scripts to set a value? I've read over some documentation for it but can't figure out how to pull the…

---

## [HELP, Interconnecting SentinelOne with Elasticsearch](https://discuss.elastic.co/t/help-interconnecting-sentinelone-with-elasticsearch/332774)

<div class="topic-metadata">

**Author:** [@Mdiouf01](https://discuss.elastic.co/u/Mdiouf01)\
**Replies:** 6\
**Last updated:** [May 23, 2023, 12:11pm UTC](https://discuss.elastic.co/t/help-interconnecting-sentinelone-with-elasticsearch/332774 "2023-05-23T12:11:34Z")

</div>

Hello, I need your help :face\_holding\_back\_tears::face\_holding\_back\_tears: I am a SOC analyst, and I want to interconnect SentinelOne with ELK SIEM. Could you help me to know if you have a tuto or clear documentation e…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=3)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=5)
