# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=5

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 6

---

## [SentinelOne integration GeoIP database error](https://discuss.elastic.co/t/sentinelone-integration-geoip-database-error/333262)

<div class="topic-metadata">

**Author:** [@Anton\_H](https://discuss.elastic.co/u/Anton_H)\
**Replies:** 2\
**Last updated:** [May 13, 2023, 2:34pm UTC](https://discuss.elastic.co/t/sentinelone-integration-geoip-database-error/333262 "2023-05-13T14:34:44Z")

</div>

Hello, We use the SentinelOne integration through fleet in our Elastic Cloud environment. Events are being received and processed. The issue is we get "\_geoip\_database\_unavailable\_GeoLite2-City.mmdb" errors on all age…

---

## [Filter Windows Device Scanning from Direct Outbound SMB Connection rule](https://discuss.elastic.co/t/filter-windows-device-scanning-from-direct-outbound-smb-connection-rule/332248)

<div class="topic-metadata">

**Author:** [@Thyrum](https://discuss.elastic.co/u/Thyrum)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 10:11pm UTC](https://discuss.elastic.co/t/filter-windows-device-scanning-from-direct-outbound-smb-connection-rule/332248 "2023-05-11T22:11:06Z")

</div>

Hi, We have been trying to filter out windows device scanning from our Direct Outbound SMB Connection rule logs. As is mentioned in the first note of Configure device discovery | Microsoft Learn, these SMB connections a…

---

## [Network scan](https://discuss.elastic.co/t/network-scan/330717)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 12:39pm UTC](https://discuss.elastic.co/t/network-scan/330717 "2023-04-27T12:39:30Z")

</div>

Hello, I try to create a rule to detect a network scan. For example, generate an alert if more than 10 unique destinations have been accessed from the same source IP within 1 minute. but I don't see how to indicate …

---

## [Extracting Detection Rule](https://discuss.elastic.co/t/extracting-detection-rule/330549)

<div class="topic-metadata">

**Author:** [@Aliz6](https://discuss.elastic.co/u/Aliz6)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 10:49am UTC](https://discuss.elastic.co/t/extracting-detection-rule/330549 "2023-04-27T10:49:20Z")

</div>

Hi there, I was wondering if there is a way to extract all of the detection use cases (built-in and custom) in an excel sheet rather a json format file. Any suggestions would be helpful. Thanks.

---

## [Packetbeat Alerts](https://discuss.elastic.co/t/packetbeat-alerts/329841)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 4:27pm UTC](https://discuss.elastic.co/t/packetbeat-alerts/329841 "2023-04-14T16:27:46Z")

</div>

I have elasticsearch, kibana and packetbeat running and I want to get alerts whenever there is abnormal activity with packetbeat information. How do I do it? My elasticsearch, kibana and packetbeat are running on-premesi…

---

## [Limit storage needs by automatically remove data after 28 days](https://discuss.elastic.co/t/limit-storage-needs-by-automatically-remove-data-after-28-days/329865)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 5:39am UTC](https://discuss.elastic.co/t/limit-storage-needs-by-automatically-remove-data-after-28-days/329865 "2023-04-13T05:39:23Z")

</div>

I have my small test environment up and running. It is collecting data from different sources. Now i wonder how i can handle the effective file storage. Only 1 node in the cluster - non productive. Is it possible to co…

---

## [Bulk alerting configuration](https://discuss.elastic.co/t/bulk-alerting-configuration/327511)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 5\
**Last updated:** [April 11, 2023, 9:13pm UTC](https://discuss.elastic.co/t/bulk-alerting-configuration/327511 "2023-04-11T21:13:48Z")

</div>

Afternoon, We are using the alerting functionality inside the Elastic Security toolset, and we have turned on about 100-odd rules. We have created email and webhook integrations and have started to tune the data being …

---

## [Integration sophos Firewall with elastic](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454)

<div class="topic-metadata">

**Author:** [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Replies:** 10\
**Last updated:** [April 9, 2023, 1:17pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454 "2023-04-09T13:17:26Z")

</div>

Dear there. Im trying to connect sophos firewall with elastic but i don't receive any logs. Im deployed an agent with sophos integration, and i followed the instructions on the elastic, i add my firewall ip instead …

---

## [Multiple index search](https://discuss.elastic.co/t/multiple-index-search/329180)

<div class="topic-metadata">

**Author:** [@Phoenix1](https://discuss.elastic.co/u/Phoenix1)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 3:43pm UTC](https://discuss.elastic.co/t/multiple-index-search/329180 "2023-04-03T15:43:28Z")

</div>

How to search logs in multiple index, within discover it does not gives option to select multiple indexes in drop down option.

---

## [Sharing Case ID value using Elastic Case Management webhook](https://discuss.elastic.co/t/sharing-case-id-value-using-elastic-case-management-webhook/328641)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 2:05pm UTC](https://discuss.elastic.co/t/sharing-case-id-value-using-elastic-case-management-webhook/328641 "2023-03-30T14:05:45Z")

</div>

Greetings! I'm on the way to implementing the automation solution for our Elastic Security Cases. While working on some automation scripts, I got a problem with the response to Cases. For example, when the Case is crea…

---

## [Feature Request for more robust vector graphics (Vega not enough) so I can generate good looking network maps (non-geographic)](https://discuss.elastic.co/t/feature-request-for-more-robust-vector-graphics-vega-not-enough-so-i-can-generate-good-looking-network-maps-non-geographic/328286)

<div class="topic-metadata">

**Author:** [@J\_Todd](https://discuss.elastic.co/u/J_Todd)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 2:15pm UTC](https://discuss.elastic.co/t/feature-request-for-more-robust-vector-graphics-vega-not-enough-so-i-can-generate-good-looking-network-maps-non-geographic/328286 "2023-03-23T14:15:15Z")

</div>

I want to be able to generate, within Kibana and / or Elastic Security, non-geographic, good looking network maps like these: Currently there doesn't seem to be any way to do this in any Elastic product no matter…

---

## [ELK Vulnerability Detection](https://discuss.elastic.co/t/elk-vulnerability-detection/327261)

<div class="topic-metadata">

**Author:** [@cyberintellect](https://discuss.elastic.co/u/cyberintellect)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 6:01am UTC](https://discuss.elastic.co/t/elk-vulnerability-detection/327261 "2023-03-10T06:01:03Z")

</div>

Hi guys, I was wondering if the function exists or is being looked at to implement vulnerability detections via the agent like with Wazuh Vulnerability Detection module. I searched the forum but I'm not seeing, might b…

---

## [How much is xpack-siem, please tell me , thanks](https://discuss.elastic.co/t/how-much-is-xpack-siem-please-tell-me-thanks/324375)

<div class="topic-metadata">

**Author:** [@dingyouqiang](https://discuss.elastic.co/u/dingyouqiang)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 1:04am UTC](https://discuss.elastic.co/t/how-much-is-xpack-siem-please-tell-me-thanks/324375 "2023-02-01T01:04:23Z")

</div>

i don't know the price of xpack and i never use them. I want to know the price , and tell my boss. thanks

---

## [Adding Fleet Server failed because “x509: certificate signed by unknown authority“](https://discuss.elastic.co/t/adding-fleet-server-failed-because-x509-certificate-signed-by-unknown-authority/323157)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 5\
**Last updated:** [January 30, 2023, 2:52pm UTC](https://discuss.elastic.co/t/adding-fleet-server-failed-because-x509-certificate-signed-by-unknown-authority/323157 "2023-01-30T14:52:52Z")

</div>

Hello, I tried to add a fleet server today on a CentOS Server. Because I don’t want to add Agents with the —insecure flag anymore, I followed this documentation step by step: I created the ca.crt that signed the fleet…

---

## [Detecting inactive users in Active Directory](https://discuss.elastic.co/t/detecting-inactive-users-in-active-directory/323650)

<div class="topic-metadata">

**Author:** [@Elnur\_Abbasov](https://discuss.elastic.co/u/Elnur_Abbasov)\
**Replies:** 5\
**Last updated:** [January 25, 2023, 12:29am UTC](https://discuss.elastic.co/t/detecting-inactive-users-in-active-directory/323650 "2023-01-25T00:29:39Z")

</div>

Hey All, I need to detect inactive users in Active Directory using Elastic SIEM. Any ideas how can I do that using EQL? I implemented the detection login in Splunk by using lookup files where I write to a lookup file al…

---

## [Excessive denied SMB traffic](https://discuss.elastic.co/t/excessive-denied-smb-traffic/323184)

<div class="topic-metadata">

**Author:** [@Abulfaz](https://discuss.elastic.co/u/Abulfaz)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 12:00am UTC](https://discuss.elastic.co/t/excessive-denied-smb-traffic/323184 "2023-01-18T00:00:55Z")

</div>

How should I write Elastic rule that detect if excessive denied SMB traffic from a single host?

---

## [Detection rules - new installation](https://discuss.elastic.co/t/detection-rules-new-installation/323165)

<div class="topic-metadata">

**Author:** [@hobbyist](https://discuss.elastic.co/u/hobbyist)\
**Replies:** 1\
**Last updated:** [January 14, 2023, 1:57am UTC](https://discuss.elastic.co/t/detection-rules-new-installation/323165 "2023-01-14T01:57:38Z")

</div>

How do I enable the Detection Engine and import the baseline detection rules in Kibana? I installed the oss version of 7.10.2 on an ubuntu server version 22.04.

---

## [Network Scan](https://discuss.elastic.co/t/network-scan/322835)

<div class="topic-metadata">

**Author:** [@Gurban](https://discuss.elastic.co/u/Gurban)\
**Replies:** 5\
**Last updated:** [January 12, 2023, 5:43pm UTC](https://discuss.elastic.co/t/network-scan/322835 "2023-01-12T17:43:35Z")

</div>

How should I write Elastic rule that detect if more than 10 unique destinations were accessed from same source IP within 1 minutes. Best Regards

---

## [ML Unsupervised question](https://discuss.elastic.co/t/ml-unsupervised-question/322437)

<div class="topic-metadata">

**Author:** [@alex\_su](https://discuss.elastic.co/u/alex_su)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 4:40pm UTC](https://discuss.elastic.co/t/ml-unsupervised-question/322437 "2023-01-09T16:40:45Z")

</div>

Hi, as i know es provide ml to detect unusual event, like "Unusual Windows Username" and another exapmle is " Unusual Hour for a User to Logon". I have question about unusual meaning as belows. how to build this ml ? …

---

## [Alerts on SIEM](https://discuss.elastic.co/t/alerts-on-siem/321297)

<div class="topic-metadata">

**Author:** [@Samara\_Brych](https://discuss.elastic.co/u/Samara_Brych)\
**Replies:** 2\
**Last updated:** [December 27, 2022, 6:34pm UTC](https://discuss.elastic.co/t/alerts-on-siem/321297 "2022-12-27T18:34:27Z")

</div>

If I mark an alert as ackowledged on Elastic SIEM, and the alert occurs again, it will notify me again or never more will display on open alerts?

---

## [CSPM third Party](https://discuss.elastic.co/t/cspm-third-party/321805)

<div class="topic-metadata">

**Author:** [@Dea\_Agra](https://discuss.elastic.co/u/Dea_Agra)\
**Replies:** 1\
**Last updated:** [December 25, 2022, 11:52pm UTC](https://discuss.elastic.co/t/cspm-third-party/321805 "2022-12-25T23:52:06Z")

</div>

Hi Elastic Team, We want to integrate our Elastic SIEM with CSPM third part tools, is there any tool recommandation taht we can integrate with our Elastic SIEM?

---

## [Getting SIEM alerts through API](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603)

<div class="topic-metadata">

**Author:** [@reg\_reginald](https://discuss.elastic.co/u/reg_reginald)\
**Replies:** 4\
**Last updated:** [December 21, 2022, 7:13pm UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603 "2022-12-21T19:13:21Z")

</div>

Hello, Is it possible to get alerts from Kibana SIEM through an api? it seems like \<kibana host\>:\<port\>/api/detection\_engine/signals could be a way but there's no example with individual alerts, just an aggregation. …

---

## [Difference between using elastic cloud (aws) and using elastic from AWS marketplace](https://discuss.elastic.co/t/difference-between-using-elastic-cloud-aws-and-using-elastic-from-aws-marketplace/320898)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 3\
**Last updated:** [December 11, 2022, 6:22am UTC](https://discuss.elastic.co/t/difference-between-using-elastic-cloud-aws-and-using-elastic-from-aws-marketplace/320898 "2022-12-11T06:22:18Z")

</div>

Hi all, I want to know the details information about difference between using elastic cloud (aws) and using elastic from our AWS marketplace?

---

## [Missing required fields in duplicated rules](https://discuss.elastic.co/t/missing-required-fields-in-duplicated-rules/320874)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [December 9, 2022, 10:22pm UTC](https://discuss.elastic.co/t/missing-required-fields-in-duplicated-rules/320874 "2022-12-09T22:22:09Z")

</div>

When I duplicate a rule, I don't immediately see an option to select required fields? (I could be looking over it?)

---

## [Best way to analyze Event Correlation Sequence detections](https://discuss.elastic.co/t/best-way-to-analyze-event-correlation-sequence-detections/320497)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 5\
**Last updated:** [December 7, 2022, 8:20pm UTC](https://discuss.elastic.co/t/best-way-to-analyze-event-correlation-sequence-detections/320497 "2022-12-07T20:20:57Z")

</div>

Hey, I want to analyse an Event Correlation rule detection (EQL) in Elastic SIEM. However, for sequence-type EQL queries, the alert details and SIEM app don't show me all the information I need to do my analysis. Consid…

---

## [Can I still use Threat Intelligence?](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 6\
**Last updated:** [November 29, 2022, 12:06am UTC](https://discuss.elastic.co/t/can-i-still-use-threat-intelligence/319962 "2022-11-29T00:06:20Z")

</div>

Hello Community, I just upgraded one of my test machines from 8.1.2 to 8.5.2 and I noticed that there is now a menu in the security section called "Intelligence", but when I click on it it says "Start a free trial or up…

---

## [KQL Comprehensive Tutorial on Event Correlation Rules](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669)

<div class="topic-metadata">

**Author:** [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Replies:** 3\
**Last updated:** [November 28, 2022, 8:05pm UTC](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669 "2022-11-28T20:05:13Z")

</div>

I need to build some rather complex rules, but I'm just getting started with KQL. I haven't found any in-depth comprehensive tuts out there on event correlation. Everything is always brief and basic. Anyone know of any g…

---

## [EQL without pre defined field values](https://discuss.elastic.co/t/eql-without-pre-defined-field-values/318871)

<div class="topic-metadata">

**Author:** [@frederikvandeputte](https://discuss.elastic.co/u/frederikvandeputte)\
**Replies:** 1\
**Last updated:** [November 28, 2022, 7:45pm UTC](https://discuss.elastic.co/t/eql-without-pre-defined-field-values/318871 "2022-11-28T19:45:57Z")

</div>

Hi I am in a process of migrating correlation rules from a McAfee SIEM to Elastic Security and I am checking if it is possible to build the following use case in EQL: I am looking at events generated by a security solu…

---

## [Problems With Import-Rules and Create-Rules](https://discuss.elastic.co/t/problems-with-import-rules-and-create-rules/317410)

<div class="topic-metadata">

**Author:** [@Omar\_E](https://discuss.elastic.co/u/Omar_E)\
**Replies:** 1\
**Last updated:** [November 12, 2022, 10:51pm UTC](https://discuss.elastic.co/t/problems-with-import-rules-and-create-rules/317410 "2022-11-12T22:51:34Z")

</div>

I am currently trying to use the detection-rules CLI tool to import or create-rules from a JSON file. However, I keep getting the error below. Does anyone know how to fix this?

---

## [Unable to get rule triggered](https://discuss.elastic.co/t/unable-to-get-rule-triggered/317448)

<div class="topic-metadata">

**Author:** [@GUruisaDog](https://discuss.elastic.co/u/GUruisaDog)\
**Replies:** 6\
**Last updated:** [November 10, 2022, 8:53pm UTC](https://discuss.elastic.co/t/unable-to-get-rule-triggered/317448 "2022-11-10T20:53:34Z")

</div>

My current version of ES Security is on 7.16.1. I was trying to setup a threshold rule, and everything goes well. I could see the result from the preview and such. However, after created the rule and activate the rule, n…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=4)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=6)
