# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=7

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 8

---

## [Creating processor \[set\_security\_user\] (tag \[null\]) on field \[\_security\] but authentication is not currently enabled](https://discuss.elastic.co/t/creating-processor-set-security-user-tag-null-on-field-security-but-authentication-is-not-currently-enabled/306706)

<div class="topic-metadata">

**Author:** [@K\_st\_rs](https://discuss.elastic.co/u/K_st_rs)\
**Replies:** 7\
**Last updated:** [June 27, 2022, 10:38am UTC](https://discuss.elastic.co/t/creating-processor-set-security-user-tag-null-on-field-security-but-authentication-is-not-currently-enabled/306706 "2022-06-27T10:38:30Z")

</div>

Logs are filled every 4 minutes with below message on a test server and there is no help on this. I am fairly new to this and wouldn't have edited any files to a big extent. There is another thread on here (discuss.elast…

---

## [Parse json file](https://discuss.elastic.co/t/parse-json-file/307291)

<div class="topic-metadata">

**Author:** [@Roshan1](https://discuss.elastic.co/u/Roshan1)\
**Replies:** 0\
**Last updated:** [June 15, 2022, 2:53pm UTC](https://discuss.elastic.co/t/parse-json-file/307291 "2022-06-15T14:53:01Z")

</div>

Hello Team, grateful if you can help for the json parser. How can I modify the code below as per sample code? input { file { start\_position =\> "beginning" path =\> "/data/KONG1/logs/b0197a09e1f3d7de67d47bdbc5f33f5b06…

---

## [Create new Event Renderers](https://discuss.elastic.co/t/create-new-event-renderers/307382)

<div class="topic-metadata">

**Author:** [@kotvmrc](https://discuss.elastic.co/u/kotvmrc)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 3:36pm UTC](https://discuss.elastic.co/t/create-new-event-renderers/307382 "2022-06-16T15:36:34Z")

</div>

Hi guys, I'm looking for creating/customizing "Events Renderers" the ones used inside the timelines or in the "Alerts" page. I've found only a little piece of configuration where I can select what renderer enable or no…

---

## [Security Events Filters vs. Ingest Node Pipelines](https://discuss.elastic.co/t/security-events-filters-vs-ingest-node-pipelines/306447)

<div class="topic-metadata">

**Author:** [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Replies:** 0\
**Last updated:** [June 6, 2022, 12:33pm UTC](https://discuss.elastic.co/t/security-events-filters-vs-ingest-node-pipelines/306447 "2022-06-06T12:33:31Z")

</div>

Hi, What are the pros and cons of using Security Event Filters over the Ingest Node Pipelines for dropping unwanted log data? Ingest Pipelines seem to allow more granularity.

---

## [Cloudflare integration Logpull not working](https://discuss.elastic.co/t/cloudflare-integration-logpull-not-working/306017)

<div class="topic-metadata">

**Author:** [@Guncixx](https://discuss.elastic.co/u/Guncixx)\
**Replies:** 2\
**Last updated:** [June 1, 2022, 5:45am UTC](https://discuss.elastic.co/t/cloudflare-integration-logpull-not-working/306017 "2022-06-01T05:45:20Z")

</div>

I have cloudflare integration set up and configured both audit logs and logpull logs, for some time it worked without a problem but couple days ago logpull logs stopped coming in. Nothing has been changed in integration …

---

## [Kibana -\> Security -\> elastic rules space issue](https://discuss.elastic.co/t/kibana-security-elastic-rules-space-issue/301861)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 4\
**Last updated:** [May 20, 2022, 9:19am UTC](https://discuss.elastic.co/t/kibana-security-elastic-rules-space-issue/301861 "2022-05-20T09:19:27Z")

</div>

Hello Experts, I need some more insight on .siem-security index creation by kibana. We have created 3 spaces in kibana and enabled the same Security -\> elastic rules under all 3 spaces (eg: Whitespace Padding in Proces…

---

## [Event analyzer showing error](https://discuss.elastic.co/t/event-analyzer-showing-error/304930)

<div class="topic-metadata">

**Author:** [@okopnik](https://discuss.elastic.co/u/okopnik)\
**Replies:** 0\
**Last updated:** [May 17, 2022, 11:42am UTC](https://discuss.elastic.co/t/event-analyzer-showing-error/304930 "2022-05-17T11:42:45Z")

</div>

Hello, We're running an elastic stack consisting of Winlogbeat (7.16.1), Logstash (7.17.2), Elastic (7.17.2) and Kibana (7.17.2) nodes. We tried using the Timeline feature and analyzing events, but it prompts an error …

---

## [Create backup siem server with same integration](https://discuss.elastic.co/t/create-backup-siem-server-with-same-integration/304926)

<div class="topic-metadata">

**Author:** [@indrajit\_kal](https://discuss.elastic.co/u/indrajit_kal)\
**Replies:** 0\
**Last updated:** [May 17, 2022, 11:22am UTC](https://discuss.elastic.co/t/create-backup-siem-server-with-same-integration/304926 "2022-05-17T11:22:25Z")

</div>

if my live siem server is crash than how i connect my all elastic agent on new server which working on same elastic&kibana certificate and same IP. elastic version 7.17.\* please guide is it work or not. Thanks & regar…

---

## [Seperate email alerts per detection?](https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112)

<div class="topic-metadata">

**Author:** [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Replies:** 2\
**Last updated:** [May 17, 2022, 8:58am UTC](https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112 "2022-05-17T08:58:23Z")

</div>

Hi Everyone, I've been doing some testing with the Email Alerts, to alert us when a specific event code is generated. I've done this under Security \> Rules, and it runs every 5 minutes. It works absolutely fine but the…

---

## [Automaticaly close SIEM case](https://discuss.elastic.co/t/automaticaly-close-siem-case/304195)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [May 9, 2022, 2:25am UTC](https://discuss.elastic.co/t/automaticaly-close-siem-case/304195 "2022-05-09T02:25:11Z")

</div>

Hi all, I am tryiing to use shuffle soar to automate some of the task in the SIEM. One of them is the create and close cases. when i run the playbook the close case keep giving me error like this: These cases id has …

---

## [Get events of an specific rule](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073)

<div class="topic-metadata">

**Author:** [@Felipe\_Fuller](https://discuss.elastic.co/u/Felipe_Fuller)\
**Replies:** 3\
**Last updated:** [May 6, 2022, 2:43am UTC](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073 "2022-05-06T02:43:16Z")

</div>

Hi Community! I'm trying to obtain all the events of a specific rule. Since I didn't find an API that does the job, I inspected the Chome Network Dev tool. During the inspection, I saw a request done to /internal/bsearc…

---

## [Remove Ingest Processor](https://discuss.elastic.co/t/remove-ingest-processor/303848)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 0\
**Last updated:** [May 3, 2022, 2:47pm UTC](https://discuss.elastic.co/t/remove-ingest-processor/303848 "2022-05-03T14:47:25Z")

</div>

I'm looking to re-index the .siem-signals-default index into an index called alerts and have created a pipeline to remove fields from the .siem-signals-default index. It looks similar to below - However, it doesn't …

---

## [Machine Learning Functionality Across Clusters](https://discuss.elastic.co/t/machine-learning-functionality-across-clusters/302514)

<div class="topic-metadata">

**Author:** [@Datt\_Mamon](https://discuss.elastic.co/u/Datt_Mamon)\
**Replies:** 3\
**Last updated:** [April 15, 2022, 7:33pm UTC](https://discuss.elastic.co/t/machine-learning-functionality-across-clusters/302514 "2022-04-15T19:33:07Z")

</div>

Hello Elastic Community! Running into an issue in my environment that I was hoping y'all could help with. My current architecture is divided into 3 clusters: RED1, BLUE1, and my Cross Cluster Search (CCS) cluster that h…

---

## [Email trace logs in the Microsoft Office 365 integration](https://discuss.elastic.co/t/email-trace-logs-in-the-microsoft-office-365-integration/301649)

<div class="topic-metadata">

**Author:** [@dsv](https://discuss.elastic.co/u/dsv)\
**Replies:** 1\
**Last updated:** [April 14, 2022, 8:17am UTC](https://discuss.elastic.co/t/email-trace-logs-in-the-microsoft-office-365-integration/301649 "2022-04-14T08:17:05Z")

</div>

Hello, Is it possible to get the email trace logs (delivery status, sender, recipient, subject and attachments fields) in the Microsoft Office 365 integration in the Kibana 7.16.3? Some of these fields are presented at…

---

## [How to add client.ip to Alarm "stack by"?](https://discuss.elastic.co/t/how-to-add-client-ip-to-alarm-stack-by/302171)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 1\
**Last updated:** [April 12, 2022, 1:12pm UTC](https://discuss.elastic.co/t/how-to-add-client-ip-to-alarm-stack-by/302171 "2022-04-12T13:12:43Z")

</div>

In the "Alerts" section, in the "Stack by" field, I see many fields other than the one I need (client.ip). How to add a field to this list?

---

## [Timeline Template not applied when Alert fires](https://discuss.elastic.co/t/timeline-template-not-applied-when-alert-fires/301950)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 8\
**Last updated:** [April 12, 2022, 7:41am UTC](https://discuss.elastic.co/t/timeline-template-not-applied-when-alert-fires/301950 "2022-04-12T07:41:56Z")

</div>

Hi I am having issues with timeline templates. I have built a custom template showing some specific fields I would be interested in for blocked sessions thorugh a firewall. The timeline is configured and in the timeli…

---

## [Issue with rules creation](https://discuss.elastic.co/t/issue-with-rules-creation/301083)

<div class="topic-metadata">

**Author:** [@kesako](https://discuss.elastic.co/u/kesako)\
**Replies:** 14\
**Last updated:** [April 7, 2022, 1:56pm UTC](https://discuss.elastic.co/t/issue-with-rules-creation/301083 "2022-04-07T13:56:13Z")

</div>

Hello, I am trying to test some features of the SIEM integrated in ELK but I am stuck on the rules. In fact I am trying to put a rule where a alert is sent when a specific ip receives packets from another specific ip…

---

## [AWS VPC Flow Log integration](https://discuss.elastic.co/t/aws-vpc-flow-log-integration/301712)

<div class="topic-metadata">

**Author:** [@ame123](https://discuss.elastic.co/u/ame123)\
**Replies:** 0\
**Last updated:** [April 6, 2022, 7:20am UTC](https://discuss.elastic.co/t/aws-vpc-flow-log-integration/301712 "2022-04-06T07:20:44Z")

</div>

Hi all, We have been trying since a month to stabilize the integration of vpc flow logs using elastic agent. There is always a lag of 2-3 days in the ingestion, the messages in the sqs queue never seems to do down beca…

---

## [Cisco Umbrella logs ingestion - Elastic Cloud](https://discuss.elastic.co/t/cisco-umbrella-logs-ingestion-elastic-cloud/301530)

<div class="topic-metadata">

**Author:** [@misiel](https://discuss.elastic.co/u/misiel)\
**Replies:** 4\
**Last updated:** [April 5, 2022, 1:21pm UTC](https://discuss.elastic.co/t/cisco-umbrella-logs-ingestion-elastic-cloud/301530 "2022-04-05T13:21:02Z")

</div>

Hello I started Elastic Cloud service trial period. I want to ingest Cisco Umbrella logs using Cisco Umbrella integration. Documentation says, that I have to install Elastic Agent in order to ship the logs (logs from se…

---

## [Edit pre-build rule](https://discuss.elastic.co/t/edit-pre-build-rule/301515)

<div class="topic-metadata">

**Author:** [@marti1](https://discuss.elastic.co/u/marti1)\
**Replies:** 1\
**Last updated:** [April 4, 2022, 4:08pm UTC](https://discuss.elastic.co/t/edit-pre-build-rule/301515 "2022-04-04T16:08:28Z")

</div>

Hi, Is it possible to edit pre-build rules? I would like to configure the output action (index connector) for each pre-build rule. It depends on the license? My current stack version: 7.16.2 Thx

---

## [Enabled building block option on rule but still mamy tickets](https://discuss.elastic.co/t/enabled-building-block-option-on-rule-but-still-mamy-tickets/301387)

<div class="topic-metadata">

**Author:** [@realtech2338](https://discuss.elastic.co/u/realtech2338)\
**Replies:** 0\
**Last updated:** [April 2, 2022, 12:02pm UTC](https://discuss.elastic.co/t/enabled-building-block-option-on-rule-but-still-mamy-tickets/301387 "2022-04-02T12:02:33Z")

</div>

The main pain for our analyst is noise. For instance we have brute force rules if it matches 100+ hits we need to get one ticket but we are getting 100 tickets generated on out ticketing tool zendesk. I have even enabled…

---

## [Multi-tenancy in ES 8+](https://discuss.elastic.co/t/multi-tenancy-in-es-8/301132)

<div class="topic-metadata">

**Author:** [@tfriesen](https://discuss.elastic.co/u/tfriesen)\
**Replies:** 2\
**Last updated:** [March 30, 2022, 5:44pm UTC](https://discuss.elastic.co/t/multi-tenancy-in-es-8/301132 "2022-03-30T17:44:25Z")

</div>

Hi there I'm the process of architecting out a SIEM-as-a-service offering using Elasticsearch+Fleet, but I'm having a hard time finding good, recent documentation on multi-tenancy for modern versions of Elasticsearch an…

---

## [Elastic Detection Actions - any way to add fields?](https://discuss.elastic.co/t/elastic-detection-actions-any-way-to-add-fields/300764)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 1\
**Last updated:** [March 28, 2022, 2:08pm UTC](https://discuss.elastic.co/t/elastic-detection-actions-any-way-to-add-fields/300764 "2022-03-28T14:08:22Z")

</div>

We are creating numerous threshold detections for a specific client. This client is asking the threshold detections to email them when the alert is triggered, but they are asking us to include details about the original…

---

## [Enable email Alerts for High Severity Detections](https://discuss.elastic.co/t/enable-email-alerts-for-high-severity-detections/300320)

<div class="topic-metadata">

**Author:** [@jbal24](https://discuss.elastic.co/u/jbal24)\
**Replies:** 2\
**Last updated:** [March 28, 2022, 11:59am UTC](https://discuss.elastic.co/t/enable-email-alerts-for-high-severity-detections/300320 "2022-03-28T11:59:44Z")

</div>

Hi All, How can I enable email Alerts for ALL High Severity Detections? Best regards,

---

## [Rules don't trigger and preview window is empty](https://discuss.elastic.co/t/rules-dont-trigger-and-preview-window-is-empty/300137)

<div class="topic-metadata">

**Author:** [@Alex\_Bailey](https://discuss.elastic.co/u/Alex_Bailey)\
**Replies:** 6\
**Last updated:** [March 24, 2022, 9:26am UTC](https://discuss.elastic.co/t/rules-dont-trigger-and-preview-window-is-empty/300137 "2022-03-24T09:26:19Z")

</div>

Working with Elastic 8.1 stack and I can't seem to get rules to work for me no matter what I try. I have a rule defined as so: When I run the preview, this brings back no results: The request generated in this q…

---

## [Elastic Security Rule exception](https://discuss.elastic.co/t/elastic-security-rule-exception/300273)

<div class="topic-metadata">

**Author:** [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Replies:** 1\
**Last updated:** [March 22, 2022, 12:20pm UTC](https://discuss.elastic.co/t/elastic-security-rule-exception/300273 "2022-03-22T12:20:25Z")

</div>

Hi, I have been using elastic security as a SIEM for my organization for some time. Due to insufficient space, I had deleted one index. Thereafter I saw failures of the detection rules which was not the case before. Be…

---

## [Update field on all SIEM detection Rules in one go](https://discuss.elastic.co/t/update-field-on-all-siem-detection-rules-in-one-go/299862)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 5\
**Last updated:** [March 21, 2022, 10:10pm UTC](https://discuss.elastic.co/t/update-field-on-all-siem-detection-rules-in-one-go/299862 "2022-03-21T22:10:29Z")

</div>

Hello all, We have created almost 400 + security rule under SIEM tab in Kibana. Now the new requirement come like they need to update one common field present in all the 400 rules. Can any one guide me how to achieve t…

---

## [Migration from ELK to Azure Sentinel](https://discuss.elastic.co/t/migration-from-elk-to-azure-sentinel/299703)

<div class="topic-metadata">

**Author:** [@tipper1510](https://discuss.elastic.co/u/tipper1510)\
**Replies:** 0\
**Last updated:** [March 15, 2022, 8:57am UTC](https://discuss.elastic.co/t/migration-from-elk-to-azure-sentinel/299703 "2022-03-15T08:57:57Z")

</div>

Hi, Wondering if there is any documents/process for ingesting events from elk to Azure Sentinel as part of a migration process. So the first step is to ensure any event raised in elk is sent to Azure so it can still be …

---

## [Send sophos logs via filebeat to elasticsearch ( ubuntu 20.04 )](https://discuss.elastic.co/t/send-sophos-logs-via-filebeat-to-elasticsearch-ubuntu-20-04/299641)

<div class="topic-metadata">

**Author:** [@khouloud1](https://discuss.elastic.co/u/khouloud1)\
**Replies:** 1\
**Last updated:** [March 14, 2022, 5:17pm UTC](https://discuss.elastic.co/t/send-sophos-logs-via-filebeat-to-elasticsearch-ubuntu-20-04/299641 "2022-03-14T17:17:25Z")

</div>

Hello , I have ubuntu 20.04 and want to send sophos (antivirus) logs via filebeat to Elasticsearch . I know that the module of sophos is supported by default for firewall and utm . Could you help please

---

## [Parsing message field from CEF logs](https://discuss.elastic.co/t/parsing-message-field-from-cef-logs/298392)

<div class="topic-metadata">

**Author:** [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Replies:** 4\
**Last updated:** [March 8, 2022, 8:54am UTC](https://discuss.elastic.co/t/parsing-message-field-from-cef-logs/298392 "2022-03-08T08:54:45Z")

</div>

Hello all! I am really new to this whole Elasticsearch field. I have come across problem. I have built my Elastic SIEM laboratory and I have logs from on of my other products - Secret Server. I\`m receiving the logs just…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=6)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=8)
