# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=8

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 9

---

## [Missing index .siem-signals-default](https://discuss.elastic.co/t/missing-index-siem-signals-default/298452)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 4\
**Last updated:** [March 7, 2022, 7:38pm UTC](https://discuss.elastic.co/t/missing-index-siem-signals-default/298452 "2022-03-07T19:38:50Z")

</div>

Having 7.16.3 properly licensed with Platinum, I cannot run some (tried five) ML-rules from Security due to: ".siem-signals-default" missing. I have Elastic Agent deployed with Security Endpoint activated and lots of d…

---

## [Over 110 detections crash SIEM application and Kibana plugins](https://discuss.elastic.co/t/over-110-detections-crash-siem-application-and-kibana-plugins/295830)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 18\
**Last updated:** [March 7, 2022, 5:59pm UTC](https://discuss.elastic.co/t/over-110-detections-crash-siem-application-and-kibana-plugins/295830 "2022-03-07T17:59:03Z")

</div>

Hello, I am having an issue that I have not been able to fix, and have not even been able to understand the underlying issue. I am running a cluster with 6 hot data nodes (virtual, SSD, 16 cpus, 64gb ram and 8TB disks) …

---

## [Elastic Agent 8.0.0 on macOS 12.x](https://discuss.elastic.co/t/elastic-agent-8-0-0-on-macos-12-x/297945)

<div class="topic-metadata">

**Author:** [@teamomni](https://discuss.elastic.co/u/teamomni)\
**Replies:** 3\
**Last updated:** [March 3, 2022, 6:58pm UTC](https://discuss.elastic.co/t/elastic-agent-8-0-0-on-macos-12-x/297945 "2022-03-03T18:58:03Z")

</div>

We recently have been testing the Elastic Agent on various employees’ MacBook Pros (macOS 12.x with Intel processors) and are having permission issues. During installation we followed the guidelines provided on Enable F…

---

## [Upgrading/Updating SIEM rules](https://discuss.elastic.co/t/upgrading-updating-siem-rules/298014)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 2\
**Last updated:** [February 24, 2022, 7:13am UTC](https://discuss.elastic.co/t/upgrading-updating-siem-rules/298014 "2022-02-24T07:13:16Z")

</div>

Good Morning, I am in the process of migrating a SOC from Splunk to Elastic and am going through some of the growing pains at the moment. This question is in regards to upgrading/updating SIEM rules as we upgrade our el…

---

## [EQL rules do not work but see hits](https://discuss.elastic.co/t/eql-rules-do-not-work-but-see-hits/297136)

<div class="topic-metadata">

**Author:** [@Why](https://discuss.elastic.co/u/Why)\
**Replies:** 2\
**Last updated:** [February 14, 2022, 10:45pm UTC](https://discuss.elastic.co/t/eql-rules-do-not-work-but-see-hits/297136 "2022-02-14T22:45:11Z")

</div>

Hello, I'm trying to get started with Elastic SIEM and I noticed a problem. To retrieve the logs, I use Auditbeat (for technical reasons, I can't use Elastic Agent). I have the impression that none of the rules writte…

---

## [Issue while Restore the indexes from snapshot backup](https://discuss.elastic.co/t/issue-while-restore-the-indexes-from-snapshot-backup/297047)

<div class="topic-metadata">

**Author:** [@indrajit\_kal](https://discuss.elastic.co/u/indrajit_kal)\
**Replies:** 0\
**Last updated:** [February 12, 2022, 10:34am UTC](https://discuss.elastic.co/t/issue-while-restore-the-indexes-from-snapshot-backup/297047 "2022-02-12T10:34:38Z")

</div>

\[backup\_repo:test-snapshot-2022.02.11-kxyy8jd4sumangv5kozy3q/9uLE7UaUQamgAH9pYbKAAA\] cannot restore index \[.siem-signals-default-000001\] because an open index with same name already exists in the cluster. Either close or…

---

## [Custom EQL Query where one event happened and another didnt](https://discuss.elastic.co/t/custom-eql-query-where-one-event-happened-and-another-didnt/296524)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [February 7, 2022, 9:29pm UTC](https://discuss.elastic.co/t/custom-eql-query-where-one-event-happened-and-another-didnt/296524 "2022-02-07T21:29:46Z")

</div>

Hello, Just wondering if it's possible to write an EQL query where event x happenend and event y did not happen for the same host after 0-2 minutes? Use case =\> Detecting messing with Eventlog Service Event ID 1100 is…

---

## [Feature Question around KPI Visualisation](https://discuss.elastic.co/t/feature-question-around-kpi-visualisation/296287)

<div class="topic-metadata">

**Author:** [@Gosborne](https://discuss.elastic.co/u/Gosborne)\
**Replies:** 0\
**Last updated:** [February 4, 2022, 11:50am UTC](https://discuss.elastic.co/t/feature-question-around-kpi-visualisation/296287 "2022-02-04T11:50:18Z")

</div>

I'm currently setting up Elastic Security as a single pane of glass for security information and event management. As part of this we have all our alerts being created in the detections pane with the SOC opening/closing …

---

## [Get the most out of Elastic Security - Ubuntu and Windows Servers](https://discuss.elastic.co/t/get-the-most-out-of-elastic-security-ubuntu-and-windows-servers/294977)

<div class="topic-metadata">

**Author:** [@PSFletchTheTek](https://discuss.elastic.co/u/PSFletchTheTek)\
**Replies:** 7\
**Last updated:** [January 31, 2022, 7:11pm UTC](https://discuss.elastic.co/t/get-the-most-out-of-elastic-security-ubuntu-and-windows-servers/294977 "2022-01-31T19:11:19Z")

</div>

Hi All, I'm looking at Elasticsearch security and how much I can use it. I have windows and ubuntu servers, Can anyone recommend which beats and modules are best to work with the SIEM to make sure its being feed with a…

---

## [Failing to get Detection Alerts](https://discuss.elastic.co/t/failing-to-get-detection-alerts/294032)

<div class="topic-metadata">

**Author:** [@subham](https://discuss.elastic.co/u/subham)\
**Replies:** 1\
**Last updated:** [January 27, 2022, 11:54am UTC](https://discuss.elastic.co/t/failing-to-get-detection-alerts/294032 "2022-01-27T11:54:50Z")

</div>

Hi All, I am getting below error while checking detection alerts. An error occurred during rule execution: message: "security\_exception" name: "iRule-testing2" id: "" rule id: "" signals index: ".siem-signals-security\_…

---

## [Creating a case for an alert automatically](https://discuss.elastic.co/t/creating-a-case-for-an-alert-automatically/294686)

<div class="topic-metadata">

**Author:** [@subham](https://discuss.elastic.co/u/subham)\
**Replies:** 2\
**Last updated:** [January 27, 2022, 11:52am UTC](https://discuss.elastic.co/t/creating-a-case-for-an-alert-automatically/294686 "2022-01-27T11:52:25Z")

</div>

Hey Everyone, Can anyone please tell if there's a way to create a case for an alert automatically. So that we dont have to do it manually. Thanks

---

## [Unable to seeing any lines (Host & Destination )on the Network tab in Elastic Security](https://discuss.elastic.co/t/unable-to-seeing-any-lines-host-destination-on-the-network-tab-in-elastic-security/295444)

<div class="topic-metadata">

**Author:** [@Rizwan\_Balouch](https://discuss.elastic.co/u/Rizwan_Balouch)\
**Replies:** 0\
**Last updated:** [January 26, 2022, 10:12am UTC](https://discuss.elastic.co/t/unable-to-seeing-any-lines-host-destination-on-the-network-tab-in-elastic-security/295444 "2022-01-26T10:12:31Z")

</div>

i am following the elastic blog " Collecting and analyzing Zeek data with Elastic Security" everything is working except I am not able to seeing any of the “pew pew” lines on the Network tab in Elastic Security. i ha…

---

## [Fleet and Suricata for Elastic Security](https://discuss.elastic.co/t/fleet-and-suricata-for-elastic-security/295455)

<div class="topic-metadata">

**Author:** [@Limoelou](https://discuss.elastic.co/u/Limoelou)\
**Replies:** 1\
**Last updated:** [January 26, 2022, 5:16pm UTC](https://discuss.elastic.co/t/fleet-and-suricata-for-elastic-security/295455 "2022-01-26T17:16:26Z")

</div>

Hello, I am a junior Cybersecurity Engineer and I have to build from scratch a SIEM that needs to monitor many hosts. Until now, I had several agents (filebeat, auditbeat, winlogbeat, suricata) installed on several ho…

---

## [Siem Rule Duplication - Query Not Changed Despite Rule Edit](https://discuss.elastic.co/t/siem-rule-duplication-query-not-changed-despite-rule-edit/295433)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 0\
**Last updated:** [January 26, 2022, 9:03am UTC](https://discuss.elastic.co/t/siem-rule-duplication-query-not-changed-despite-rule-edit/295433 "2022-01-26T09:03:21Z")

</div>

Hi, We are using SIEM in Kibana for threat detection. We have a rule which uses a saved query that we duplicated. On the new rule we changed chose custom query and inserted a different query in kql. What happens is tha…

---

## [SIEM News feed on securitySolution:enableNewsFeed(Advance Settings) is not working](https://discuss.elastic.co/t/siem-news-feed-on-securitysolution-enablenewsfeed-advance-settings-is-not-working/295030)

<div class="topic-metadata">

**Author:** [@Ilias\_Kou](https://discuss.elastic.co/u/Ilias_Kou)\
**Replies:** 0\
**Last updated:** [January 21, 2022, 8:34am UTC](https://discuss.elastic.co/t/siem-news-feed-on-securitysolution-enablenewsfeed-advance-settings-is-not-working/295030 "2022-01-21T08:34:34Z")

</div>

I am trying to change the default news feed from https://feeds.elastic.co/security-solution to anything on this list for example https://www.reddit.com/r/netsecstudents/comments/5rtmu1/rss\_infosec\_news/ but I find no suc…

---

## [How to aggregate alerts?](https://discuss.elastic.co/t/how-to-aggregate-alerts/294654)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 0\
**Last updated:** [January 18, 2022, 5:27am UTC](https://discuss.elastic.co/t/how-to-aggregate-alerts/294654 "2022-01-18T05:27:38Z")

</div>

So i have many alerts with the same cause (some maware send messages to C2) with the same source IP address. Can i aggregate such alerts in one (aggregation by source IP address)?

---

## [Elastic Security Integeration with Huawei firewall](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868)

<div class="topic-metadata">

**Author:** [@Rizwan\_Balouch](https://discuss.elastic.co/u/Rizwan_Balouch)\
**Replies:** 7\
**Last updated:** [January 14, 2022, 10:02am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868 "2022-01-14T10:02:59Z")

</div>

any idea about elastic security integration with Huawei firewall ? any workaround as Huawei integration is not listed in elastic security builtin integrations ?

---

## [Aggregating Case Information](https://discuss.elastic.co/t/aggregating-case-information/291836)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 4\
**Last updated:** [January 14, 2022, 12:20am UTC](https://discuss.elastic.co/t/aggregating-case-information/291836 "2022-01-14T00:20:10Z")

</div>

Hello, I would like to aggregate case information monthly into certain reports, for example, how many cases were opened in the last month, status, etc.. I know all cases are stored as saved objects, and I was looking i…

---

## [Unable to seeing any of the “pew pew” lines on the Network tab in Elastic Security](https://discuss.elastic.co/t/unable-to-seeing-any-of-the-pew-pew-lines-on-the-network-tab-in-elastic-security/294283)

<div class="topic-metadata">

**Author:** [@Rizwan\_Balouch](https://discuss.elastic.co/u/Rizwan_Balouch)\
**Replies:** 0\
**Last updated:** [January 13, 2022, 1:56pm UTC](https://discuss.elastic.co/t/unable-to-seeing-any-of-the-pew-pew-lines-on-the-network-tab-in-elastic-security/294283 "2022-01-13T13:56:49Z")

</div>

i am following the elastic blog " Collecting and analyzing Zeek data with Elastic Security" everything is working except I am not able to seeing any of the “pew pew” lines on the Network tab in Elastic Security. i hav…

---

## [No data showing in SIEM Detection tab](https://discuss.elastic.co/t/no-data-showing-in-siem-detection-tab/293712)

<div class="topic-metadata">

**Author:** [@subham](https://discuss.elastic.co/u/subham)\
**Replies:** 4\
**Last updated:** [January 11, 2022, 6:03am UTC](https://discuss.elastic.co/t/no-data-showing-in-siem-detection-tab/293712 "2022-01-11T06:03:26Z")

</div>

Hi Everyone, We have create a detection rule threshold in SIEM but it's not showing any output or alerts. We can see the results in Preview Results but no alert is scene. Please check the image below for reference and su…

---

## [Threshold Rule type - not able to send more than three field values in email action](https://discuss.elastic.co/t/threshold-rule-type-not-able-to-send-more-than-three-field-values-in-email-action/292870)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 1\
**Last updated:** [January 7, 2022, 7:25pm UTC](https://discuss.elastic.co/t/threshold-rule-type-not-able-to-send-more-than-three-field-values-in-email-action/292870 "2022-01-07T19:25:45Z")

</div>

Continuing the discussion from Threshold Rule type - not able to send more than three field values in email action:

---

## [Wazuh SIEM + Winlogbeat](https://discuss.elastic.co/t/wazuh-siem-winlogbeat/292490)

<div class="topic-metadata">

**Author:** [@IvanYboa](https://discuss.elastic.co/u/IvanYboa)\
**Replies:** 2\
**Last updated:** [January 7, 2022, 6:21pm UTC](https://discuss.elastic.co/t/wazuh-siem-winlogbeat/292490 "2022-01-07T18:21:08Z")

</div>

Hi! I'm new at Elasticsearch and I'm implementing the SIEM Wazuh. The team of wazuh has their own agent to collect the logs, but in the company where I'm working want that some machines run the Wazuh agents and other ma…

---

## [Elastic Agent No upgrade option Available](https://discuss.elastic.co/t/elastic-agent-no-upgrade-option-available/293738)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 1\
**Last updated:** [January 7, 2022, 5:09pm UTC](https://discuss.elastic.co/t/elastic-agent-no-upgrade-option-available/293738 "2022-01-07T17:09:26Z")

</div>

Hi all, I have a problem with some agents. I'm in version 7.16.1, I was able to upgrade most of my agents, but for some I have no option to upgrade.. The target systems (were the agents are installed) are redhat linux …

---

## [Linux\_anomalous\_process\_all\_hosts\_ecs apparently not only covering Linux, but full auditbeat](https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [January 6, 2022, 8:35am UTC](https://discuss.elastic.co/t/linux-anomalous-process-all-hosts-ecs-apparently-not-only-covering-linux-but-full-auditbeat/293519 "2022-01-06T08:35:45Z")

</div>

Hello, I was a bit surprised to see the "Anomalous Process For a Linux Population" SIEM rule trigger for Windows hosts. After some investigation, I noticed there is no filter for host.os.type or host.os.family or sth s…

---

## [Detection Rule - Output of a aggregation bucket should match with other types of logs in the same index](https://discuss.elastic.co/t/detection-rule-output-of-a-aggregation-bucket-should-match-with-other-types-of-logs-in-the-same-index/292869)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 1\
**Last updated:** [January 5, 2022, 1:40pm UTC](https://discuss.elastic.co/t/detection-rule-output-of-a-aggregation-bucket-should-match-with-other-types-of-logs-in-the-same-index/292869 "2022-01-05T13:40:33Z")

</div>

Continuing the discussion from Detection Rule - Output of a aggregation bucket should match with other types of logs in the same index:

---

## [Kibana SIEM and custom indexes](https://discuss.elastic.co/t/kibana-siem-and-custom-indexes/293186)

<div class="topic-metadata">

**Author:** [@ulysse31](https://discuss.elastic.co/u/ulysse31)\
**Replies:** 3\
**Last updated:** [January 4, 2022, 12:39pm UTC](https://discuss.elastic.co/t/kibana-siem-and-custom-indexes/293186 "2022-01-04T12:39:12Z")

</div>

Hello All, We have used Kibana SIEM essentially for network metadata retention, So historically, all network related metadata from various network filebeat modules (suricata, sonicwall, iptables, etc ...) ends up into s…

---

## [Netflow and IIS with Elastic](https://discuss.elastic.co/t/netflow-and-iis-with-elastic/292595)

<div class="topic-metadata">

**Author:** [@Sharjeel](https://discuss.elastic.co/u/Sharjeel)\
**Replies:** 2\
**Last updated:** [December 27, 2021, 2:14am UTC](https://discuss.elastic.co/t/netflow-and-iis-with-elastic/292595 "2021-12-27T02:14:57Z")

</div>

Hi there, I am new here and would like to clear some confusion. I would like to implement Netflow and IIS module (to capture IIS logs). Are those modules free and how can I implement them? Do I need ELK or SIEM for that…

---

## [SIEM Event Correlation rule returns no data](https://discuss.elastic.co/t/siem-event-correlation-rule-returns-no-data/291197)

<div class="topic-metadata">

**Author:** [@pruttle](https://discuss.elastic.co/u/pruttle)\
**Replies:** 3\
**Last updated:** [December 17, 2021, 9:06am UTC](https://discuss.elastic.co/t/siem-event-correlation-rule-returns-no-data/291197 "2021-12-17T09:06:06Z")

</div>

Kibana version 7.14.1 I am creating an Event Correlation rule in SIEM and the preview does not return any results. If I do the same query in Dev Tools it works. I see that the preview runs some kind of java script but …

---

## [Error activating rule (api key name is required)](https://discuss.elastic.co/t/error-activating-rule-api-key-name-is-required/291237)

<div class="topic-metadata">

**Author:** [@volundr](https://discuss.elastic.co/u/volundr)\
**Replies:** 8\
**Last updated:** [December 9, 2021, 4:22pm UTC](https://discuss.elastic.co/t/error-activating-rule-api-key-name-is-required/291237 "2021-12-09T16:22:56Z")

</div>

Hi, after following the official tutorial for enabling detection rules (Detections (beta) | SIEM Guide \[7.8\] | Elastic), I get the following error: \* \*\[action\_request\_validation\_exception\] Validation Failed: 1: api key …

---

## [Row Renderers, not rendering?](https://discuss.elastic.co/t/row-renderers-not-rendering/290092)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 2\
**Last updated:** [November 29, 2021, 9:48pm UTC](https://discuss.elastic.co/t/row-renderers-not-rendering/290092 "2021-11-29T21:48:49Z")

</div>

Hello, We have some Firewall data, that when viewed in the timeline, I'd expect the Flow row renderer to pick up and "beautify". I've attached a portion of the data for an example. Can someone explain why this would no…

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=7)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=9)
