# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=6

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 7

---

## [Exporting rules to ndjson generates incomplete file](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214)

<div class="topic-metadata">

**Author:** [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Replies:** 4\
**Last updated:** [November 9, 2022, 2:52pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214 "2022-11-09T14:52:06Z")

</div>

I'm trying to export all the 722 rules into an ndjson file, but the file is incomplete. There are two sets of rule: Elastic rules and Custom rules. I go to Security \> Overview \> Rules \> Select all 722 rules \> Bulk Actio…

---

## [Threshold rule can't group by with source.ip but only with source.ip.keyword](https://discuss.elastic.co/t/threshold-rule-cant-group-by-with-source-ip-but-only-with-source-ip-keyword/317761)

<div class="topic-metadata">

**Author:** [@Simone\_Calo](https://discuss.elastic.co/u/Simone_Calo)\
**Replies:** 10\
**Last updated:** [November 8, 2022, 11:35am UTC](https://discuss.elastic.co/t/threshold-rule-cant-group-by-with-source-ip-but-only-with-source-ip-keyword/317761 "2022-11-08T11:35:36Z")

</div>

My problem consists in defining a threshold rule in the group by field. I can only enter source.ip.keyword and not source.ip. The consequence of this is that the rule fails every time with the following error: Bu…

---

## [Transport communication between node with opendistro and node with xpack fails](https://discuss.elastic.co/t/transport-communication-between-node-with-opendistro-and-node-with-xpack-fails/317550)

<div class="topic-metadata">

**Author:** [@Rineesh\_Nallatath](https://discuss.elastic.co/u/Rineesh_Nallatath)\
**Replies:** 4\
**Last updated:** [October 31, 2022, 2:00am UTC](https://discuss.elastic.co/t/transport-communication-between-node-with-opendistro-and-node-with-xpack-fails/317550 "2022-10-31T02:00:08Z")

</div>

We do have an elastic setup (not complete stack,but elastic clusters in two sites with CCR enabled) We want to migrate from opendistro to X-pack security also upgrade ES version from 7.3 to 7.17. We use our internal AP…

---

## [Issue creating index with alert](https://discuss.elastic.co/t/issue-creating-index-with-alert/317604)

<div class="topic-metadata">

**Author:** [@Florian-LB](https://discuss.elastic.co/u/Florian-LB)\
**Replies:** 2\
**Last updated:** [October 27, 2022, 3:14pm UTC](https://discuss.elastic.co/t/issue-creating-index-with-alert/317604 "2022-10-27T15:14:30Z")

</div>

Hi, I want to setup an alert when 3 login rejections occur on the same switch in order to get this info on my dashboard. I created a threshold rule “Alerte Brute Force Cisco” that raise an alert when 3 authentications …

---

## [Data Stream not found in Data Views](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222)

<div class="topic-metadata">

**Author:** [@sakib3833](https://discuss.elastic.co/u/sakib3833)\
**Replies:** 1\
**Last updated:** [October 27, 2022, 2:22pm UTC](https://discuss.elastic.co/t/data-stream-not-found-in-data-views/317222 "2022-10-27T14:22:55Z")

</div>

I use Microsoft Defender Endpoint integration to collect logs. The agent installed perfectly and the other ID and secret key put accordingly. In the Index management section it shows that it creates Data Stream. But…

---

## [Elastic Cases events trigger an external SOAR](https://discuss.elastic.co/t/elastic-cases-events-trigger-an-external-soar/316999)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 3\
**Last updated:** [October 21, 2022, 1:08pm UTC](https://discuss.elastic.co/t/elastic-cases-events-trigger-an-external-soar/316999 "2022-10-21T13:08:43Z")

</div>

Hey all! I have a big question for you guys. Does anybody know about the opportunity to trigger an external API from the Elastic Case? I mean, Is there a way to implement some webhook or index in elastic that could col…

---

## [Document enrichment via ingest pipeline or Indicator Match rule - which is preferable?](https://discuss.elastic.co/t/document-enrichment-via-ingest-pipeline-or-indicator-match-rule-which-is-preferable/315830)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 3:15pm UTC](https://discuss.elastic.co/t/document-enrichment-via-ingest-pipeline-or-indicator-match-rule-which-is-preferable/315830 "2022-10-06T15:15:29Z")

</div>

Our elastic cluster is being used as a SIEM and is currently ingesting approximately 3x the data than originally scoped to ingest. It's working pretty hard. We have recently begun ingesting a MISP for enrichment and al…

---

## [Elastic SIEM cloud data storage location? Canadian Data Residency](https://discuss.elastic.co/t/elastic-siem-cloud-data-storage-location-canadian-data-residency/315712)

<div class="topic-metadata">

**Author:** [@DabLab](https://discuss.elastic.co/u/DabLab)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 8:13pm UTC](https://discuss.elastic.co/t/elastic-siem-cloud-data-storage-location-canadian-data-residency/315712 "2022-10-03T20:13:37Z")

</div>

I need to know if Elastic meets Canadian Data Residency requirements. Meaning the solution for a canadian company would store its data in canada. Thank you!

---

## [Errors in Kibana: plugins.securitySolution.endpoint:metadata-check-transforms-task:0.0.1](https://discuss.elastic.co/t/errors-in-kibana-plugins-securitysolution-endpoint0-0-1/314134)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 2:02pm UTC](https://discuss.elastic.co/t/errors-in-kibana-plugins-securitysolution-endpoint0-0-1/314134 "2022-09-26T14:02:46Z")

</div>

hi all! in kibana.log I see a lot of errors like \[2022-09-07T03:58:32.117+03:00\]\[WARN \]\[plugins.securitySolution.endpoint:metadata-check-transforms-task:0.0.1\] transform endpoint.metadata\_current-default-8.3.0 has fail…

---

## [Alert when an event is not followed by another](https://discuss.elastic.co/t/alert-when-an-event-is-not-followed-by-another/314527)

<div class="topic-metadata">

**Author:** [@bricevalenza](https://discuss.elastic.co/u/bricevalenza)\
**Replies:** 6\
**Last updated:** [September 26, 2022, 8:00am UTC](https://discuss.elastic.co/t/alert-when-an-event-is-not-followed-by-another/314527 "2022-09-26T08:00:05Z")

</div>

Hello, I am looking for a solution to create an alert when the following happens: An event with the field winlog.event\_id: "4202" occurs. 5 minutes later, no event with the field winlog.event\_id: "4204" was detected. …

---

## [Not able to edit rules](https://discuss.elastic.co/t/not-able-to-edit-rules/314643)

<div class="topic-metadata">

**Author:** [@UweW](https://discuss.elastic.co/u/UweW)\
**Replies:** 11\
**Last updated:** [September 20, 2022, 5:01pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643 "2022-09-20T17:01:39Z")

</div>

Hi, after updating from 8.2.3 to 8.4 it's no longer possible to edit the existing rules. Every time "Object type "siem.queryRule" is not registered." is shown. Hope somebody has an idea how to fix. another error occu…

---

## [Training Recomandtion](https://discuss.elastic.co/t/training-recomandtion/314406)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [September 19, 2022, 5:25pm UTC](https://discuss.elastic.co/t/training-recomandtion/314406 "2022-09-19T17:25:00Z")

</div>

Hi there, I am an Elastic admin for observability. I would to start with the security (SIEM) topic as well. I am a newbie in this regard. Which of this trainings would you suggest to attend at first: Onsite & Online Tra…

---

## [How to configure fleet server and enroll agents?](https://discuss.elastic.co/t/how-to-configure-fleet-server-and-enroll-agents/314314)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 5:20pm UTC](https://discuss.elastic.co/t/how-to-configure-fleet-server-and-enroll-agents/314314 "2022-09-13T17:20:35Z")

</div>

Hi, I have an ELK stack which newly installed and need to configure the fleet server from scratch.

---

## [Crete alerts for disabled accounts](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833)

<div class="topic-metadata">

**Author:** [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Replies:** 14\
**Last updated:** [September 9, 2022, 9:03pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833 "2022-09-09T21:03:47Z")

</div>

Hi, I'm trying to create alerts for the Disabled account for Azure SSO but not able to find the context to that. Disabled account checks for event.code : 4725 Failed account checks for event.code : "4625" The logs do …

---

## [Elastic Rule Connector sends a String instead of JSON to the Webhook](https://discuss.elastic.co/t/elastic-rule-connector-sends-a-string-instead-of-json-to-the-webhook/313833)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 5\
**Last updated:** [September 8, 2022, 7:18pm UTC](https://discuss.elastic.co/t/elastic-rule-connector-sends-a-string-instead-of-json-to-the-webhook/313833 "2022-09-08T19:18:13Z")

</div>

Hey there! First of all, I'd like to describe my situation. I have an Elastic Rule, that successfully creates the Alerts in the Elastic Security. Now I have configured a connector, that allows me to send those Alerts to…

---

## [EQL - Rule creation](https://discuss.elastic.co/t/eql-rule-creation/311732)

<div class="topic-metadata">

**Author:** [@Rahulvanadavsi](https://discuss.elastic.co/u/Rahulvanadavsi)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 9:10am UTC](https://discuss.elastic.co/t/eql-rule-creation/311732 "2022-08-31T09:10:35Z")

</div>

Hi, We would like to create a use case for password spraying attack and Impossible travel activity in our environment. Password Spraying Attack - Attacker tying to bruteforce using default passwords for multiple accou…

---

## [Why filebeat pipelines disappoint or SIEM missing authentication patterns](https://discuss.elastic.co/t/why-filebeat-pipelines-disappoint-or-siem-missing-authentication-patterns/307308)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 12\
**Last updated:** [August 23, 2022, 9:34am UTC](https://discuss.elastic.co/t/why-filebeat-pipelines-disappoint-or-siem-missing-authentication-patterns/307308 "2022-08-23T09:34:21Z")

</div>

Filebeat has a lot of modules and I like it but I can see that its approach to log parsing is chaotic. Almost all tests I can find for testing ingest pipelines on github missing example of messages about successful or fa…

---

## [How to send email alert to groups based on condition success using Kibana Rules](https://discuss.elastic.co/t/how-to-send-email-alert-to-groups-based-on-condition-success-using-kibana-rules/312198)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 2:53pm UTC](https://discuss.elastic.co/t/how-to-send-email-alert-to-groups-based-on-condition-success-using-kibana-rules/312198 "2022-08-16T14:53:49Z")

</div>

I have created a rule using Kibana rules, by following the below steps: Created a new rule by selecting "Rule" under the "Security" section Then selected the rule type as "Event Correlation", wherein I added the index …

---

## [Elastic Siem external alerts](https://discuss.elastic.co/t/elastic-siem-external-alerts/310918)

<div class="topic-metadata">

**Author:** [@abr4xc](https://discuss.elastic.co/u/abr4xc)\
**Replies:** 4\
**Last updated:** [August 11, 2022, 7:58pm UTC](https://discuss.elastic.co/t/elastic-siem-external-alerts/310918 "2022-08-11T19:58:33Z")

</div>

I am trying to set up a new integration for an EDR that is not listed on the Kibana integrations yet, in order to set up the external alerts for that EDR i am adding the event.kind to alert but its not showing up in the …

---

## [Problem with Detections - Custom query rule](https://discuss.elastic.co/t/problem-with-detections-custom-query-rule/311543)

<div class="topic-metadata">

**Author:** [@Yuriy\_Tsarenko](https://discuss.elastic.co/u/Yuriy_Tsarenko)\
**Replies:** 9\
**Last updated:** [August 11, 2022, 12:24pm UTC](https://discuss.elastic.co/t/problem-with-detections-custom-query-rule/311543 "2022-08-11T12:24:47Z")

</div>

Good afternoon dear community. I turn to you with the following problem. The custom rule does not create security alerts, although it works without visible errors. Kibana Version: 8.3.1 Rule type: custom query. Rule …

---

## [Illegal\_argument\_exception](https://discuss.elastic.co/t/illegal-argument-exception/311847)

<div class="topic-metadata">

**Author:** [@Carlos\_Vinicius](https://discuss.elastic.co/u/Carlos_Vinicius)\
**Replies:** 2\
**Last updated:** [August 11, 2022, 11:59am UTC](https://discuss.elastic.co/t/illegal-argument-exception/311847 "2022-08-11T11:59:12Z")

</div>

Dears, good morning! I'm facing the error below, can someone shed some light on me? { "took": 461, "timed\_out": false, "\_shards": { "total": 39, "successful": 38, "skipped": 33, "failed": 1, "failures": \[ { …

---

## [Export rules into excel or CSV or PDF format](https://discuss.elastic.co/t/export-rules-into-excel-or-csv-or-pdf-format/311180)

<div class="topic-metadata">

**Author:** [@sunith](https://discuss.elastic.co/u/sunith)\
**Replies:** 2\
**Last updated:** [August 3, 2022, 6:29am UTC](https://discuss.elastic.co/t/export-rules-into-excel-or-csv-or-pdf-format/311180 "2022-08-03T06:29:54Z")

</div>

Hi, Kindly let me know is there a way to export all rules into readable CSV or excel or PDF format? Or is there a way to convert .ndjson export format to CSV or excel? Thanks in advance.

---

## [Managing event filters outside the UI](https://discuss.elastic.co/t/managing-event-filters-outside-the-ui/310762)

<div class="topic-metadata">

**Author:** [@ryanturner03](https://discuss.elastic.co/u/ryanturner03)\
**Replies:** 3\
**Last updated:** [July 27, 2022, 10:12pm UTC](https://discuss.elastic.co/t/managing-event-filters-outside-the-ui/310762 "2022-07-27T22:12:37Z")

</div>

Hi all, I'm looking for a way to manage event filters across a number of deployments. Is there any API available to create / manage those or can it only be done in the UI? The feature I'm referring to:

---

## [Security events and rules matching](https://discuss.elastic.co/t/security-events-and-rules-matching/309922)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 2\
**Last updated:** [July 26, 2022, 4:49pm UTC](https://discuss.elastic.co/t/security-events-and-rules-matching/309922 "2022-07-26T16:49:20Z")

</div>

We are trying to understand what security events Elastic SIEM covers but it’s quite difficult cause there is no list of such events in the documentation or may be we don’t know where it is. We've decided to start with Wi…

---

## [SIEM - Network scan](https://discuss.elastic.co/t/siem-network-scan/309691)

<div class="topic-metadata">

**Author:** [@ldmontoya](https://discuss.elastic.co/u/ldmontoya)\
**Replies:** 3\
**Last updated:** [July 22, 2022, 9:13am UTC](https://discuss.elastic.co/t/siem-network-scan/309691 "2022-07-22T09:13:47Z")

</div>

Hi guys! I'm setting up the SIEM feature on kibana and one of my use cases is to detect network scans using nmap or any other tool. After digging on the community I've found the following threshold rule: Query: event.c…

---

## [Creating a rule exception](https://discuss.elastic.co/t/creating-a-rule-exception/310292)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 1\
**Last updated:** [July 21, 2022, 10:44pm UTC](https://discuss.elastic.co/t/creating-a-rule-exception/310292 "2022-07-21T22:44:18Z")

</div>

Hello there, I would like to know if is possible creating a rule exception like: source.ip:192.168.0.1/24 destionation.ip:200.1.0.0.0/24 This kind of rule is to apply to the "SMB (Windows File Sharing) Activity to th…

---

## [Indicator Match Rule Failing from Rule Name](https://discuss.elastic.co/t/indicator-match-rule-failing-from-rule-name/309232)

<div class="topic-metadata">

**Author:** [@codewriterguy](https://discuss.elastic.co/u/codewriterguy)\
**Replies:** 6\
**Last updated:** [July 13, 2022, 10:43pm UTC](https://discuss.elastic.co/t/indicator-match-rule-failing-from-rule-name/309232 "2022-07-13T22:43:54Z")

</div>

Hi, I created an indicator match rule using intel from the Recorded Future integration package v1.0.1. The match rule appears to be failing from the rule name itself. Here is the error output: Rule failure at Jul 8, 2…

---

## [Event filter for Elastict Agent and Endpoint Security](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429)

<div class="topic-metadata">

**Author:** [@Axel\_zendata](https://discuss.elastic.co/u/Axel_zendata)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 5:48am UTC](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429 "2022-07-13T05:48:08Z")

</div>

Dear all, I created lot of event filter in Security -\> Event Filter for the Elastic Endpoint Agent, but it 's still impossible to use regular expression to exclude event (except for file.path.text). Do you have an id…

---

## [Indicator Match Rule Fails with too\_many\_nested\_clauses](https://discuss.elastic.co/t/indicator-match-rule-fails-with-too-many-nested-clauses/309233)

<div class="topic-metadata">

**Author:** [@codewriterguy](https://discuss.elastic.co/u/codewriterguy)\
**Replies:** 4\
**Last updated:** [July 12, 2022, 9:46pm UTC](https://discuss.elastic.co/t/indicator-match-rule-fails-with-too-many-nested-clauses/309233 "2022-07-12T21:46:03Z")

</div>

Hi, I created an indicator match rule using intel from the Recorded Future integration package v1.0.1 I am getting the following failure when the rule runs: Bulk Indexing of signals failed: ResponseError: search\_phase…

---

## [Elastic SIEM miss leading text on analyzer](https://discuss.elastic.co/t/elastic-siem-miss-leading-text-on-analyzer/309150)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 2\
**Last updated:** [July 7, 2022, 9:02pm UTC](https://discuss.elastic.co/t/elastic-siem-miss-leading-text-on-analyzer/309150 "2022-07-07T21:02:22Z")

</div>

Elastic Endpoint is Detect mode. All SIEM triggered alerts do the same for Endpoint injected events. Detect and Prevent should be clearly marked. In this example "Suspicious WMI Image Load from MS Office" is going to b…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=5)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=7)
