# SIEM

**URL:** https://discuss.elastic.co/c/security/siem/78.md?page=9

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 10

---

## [Elastic SIEM. Security rules doesn't work](https://discuss.elastic.co/t/elastic-siem-security-rules-doesnt-work/290094)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Esin](https://discuss.elastic.co/u/Dmitriy_Esin)\
**Replies:** 11\
**Last updated:** [November 29, 2021, 7:58pm UTC](https://discuss.elastic.co/t/elastic-siem-security-rules-doesnt-work/290094 "2021-11-29T19:58:38Z")

</div>

Hi all! I have an issue with the Elastic Security Rules. I've installed the elastic agents on my target instances: I can successfully see its data streams: I've created default enrolment policy for my agents: …

---

## [Elastic SIEM Network Map Layers Issues](https://discuss.elastic.co/t/elastic-siem-network-map-layers-issues/289782)

<div class="topic-metadata">

**Author:** [@fmaginga](https://discuss.elastic.co/u/fmaginga)\
**Replies:** 0\
**Last updated:** [November 22, 2021, 8:14am UTC](https://discuss.elastic.co/t/elastic-siem-network-map-layers-issues/289782 "2021-11-22T08:14:41Z")

</div>

Hello, I have been experiencing some issues with Elastic SIEM Network Map Layers. I have configured only indices corporatepfw-ecs-\* from which the SIEM app collects events. See the image below. However, In the SIEM \>…

---

## [Detection Rule Export API not working](https://discuss.elastic.co/t/detection-rule-export-api-not-working/287548)

<div class="topic-metadata">

**Author:** [@tejas.tech](https://discuss.elastic.co/u/tejas.tech)\
**Replies:** 2\
**Last updated:** [November 18, 2021, 12:44am UTC](https://discuss.elastic.co/t/detection-rule-export-api-not-working/287548 "2021-11-18T00:44:23Z")

</div>

I would like to export all detection rule with details, and I did check with "Kibana IP: port/api/detection\_engine/rules/\_export", when I check with this I am getting 404 error with not found. Could anyone please help …

---

## [Webhook body format for threshold term value](https://discuss.elastic.co/t/webhook-body-format-for-threshold-term-value/287894)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 6\
**Last updated:** [November 10, 2021, 6:59pm UTC](https://discuss.elastic.co/t/webhook-body-format-for-threshold-term-value/287894 "2021-11-10T18:59:55Z")

</div>

Hi all. I've just created a webhooks to an internal services that will need to get the value as the result of the signal that a siem threshold rule will produce. Normally for email connector the body will look like thi…

---

## [Feedback for 100Gbit/s Elastic SIEM design (which includes Suricata)](https://discuss.elastic.co/t/feedback-for-100gbit-s-elastic-siem-design-which-includes-suricata/288724)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 0\
**Last updated:** [November 9, 2021, 8:43am UTC](https://discuss.elastic.co/t/feedback-for-100gbit-s-elastic-siem-design-which-includes-suricata/288724 "2021-11-09T08:43:01Z")

</div>

Is cross-posting allowed here? If so, then I would like to hear some feedback on the topic below. You may reply on this Discourse instance, or the Suricata one of course.

---

## [Json in alert result (message)](https://discuss.elastic.co/t/json-in-alert-result-message/288145)

<div class="topic-metadata">

**Author:** [@Alexey\_Shalin](https://discuss.elastic.co/u/Alexey_Shalin)\
**Replies:** 0\
**Last updated:** [November 1, 2021, 2:01pm UTC](https://discuss.elastic.co/t/json-in-alert-result-message/288145 "2021-11-01T14:01:55Z")

</div>

Good Day I have alerts in SIEM based on built-in rules. In Action Tab for Rule I setuped : Send Alert to Email and using this : {{#context.alerts}} Username: {{user.name}} Host: {{host.name}} {{/context.alerts}} Ev…

---

## [Security rules failing (timed out) all the time](https://discuss.elastic.co/t/security-rules-failing-timed-out-all-the-time/285681)

<div class="topic-metadata">

**Author:** [@syunusic](https://discuss.elastic.co/u/syunusic)\
**Replies:** 5\
**Last updated:** [November 1, 2021, 4:05pm UTC](https://discuss.elastic.co/t/security-rules-failing-timed-out-all-the-time/285681 "2021-11-01T16:05:27Z")

</div>

I have a testing Elasticsearch (7.14.0 before and 7.15.0 now) where I'm sending filebeat's Threat Intel data (50,000 documents on the filebeat-\* index) and a Firewall data index with less than 1,000,000 messages. I've c…

---

## [Set Elastic Security rules on syslog](https://discuss.elastic.co/t/set-elastic-security-rules-on-syslog/288012)

<div class="topic-metadata">

**Author:** [@Limoelou](https://discuss.elastic.co/u/Limoelou)\
**Replies:** 2\
**Last updated:** [November 1, 2021, 11:01am UTC](https://discuss.elastic.co/t/set-elastic-security-rules-on-syslog/288012 "2021-11-01T11:01:33Z")

</div>

Hello, I'm having trouble to display syslog events in Kibana. I have a Stormshield firewall sending syslog events to my elastic server from different hosts : 2628 2703 3.429885364 192.168.3.223 → 10.22.5.58 Syslog …

---

## [How to track cases in a dashboard?](https://discuss.elastic.co/t/how-to-track-cases-in-a-dashboard/287259)

<div class="topic-metadata">

**Author:** [@elasticfran](https://discuss.elastic.co/u/elasticfran)\
**Replies:** 1\
**Last updated:** [November 1, 2021, 10:36am UTC](https://discuss.elastic.co/t/how-to-track-cases-in-a-dashboard/287259 "2021-11-01T10:36:49Z")

</div>

Hello there! Is there a way to track cases in a dashboard? Like having a panel for: open cases cases in progress pending cases new cases Tried the tutorial: but i happen not to have the option "add a les" visuali…

---

## [Elasticsearch SIEM is not working, but EQL query is ok](https://discuss.elastic.co/t/elasticsearch-siem-is-not-working-but-eql-query-is-ok/287590)

<div class="topic-metadata">

**Author:** [@Dalador](https://discuss.elastic.co/u/Dalador)\
**Replies:** 1\
**Last updated:** [October 29, 2021, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-siem-is-not-working-but-eql-query-is-ok/287590 "2021-10-29T13:54:11Z")

</div>

I got some problems with my ELK running on docker. I made ssl on tls and http and tryied to make simple EQL-query: sequence by winlog.computer\_name \[iam where event.code == "4720"\] \[iam where event.code == "4726"\] Wh…

---

## [Security error after re-install of ElasticSearch](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 4\
**Last updated:** [October 27, 2021, 12:16pm UTC](https://discuss.elastic.co/t/security-error-after-re-install-of-elasticsearch/287593 "2021-10-27T12:16:37Z")

</div>

Good Morning I have been receiving multiple messages that read Error: \[object Object\]: shard\_not\_found\_exception at http://10.12.36.50:5601/41022/bundles/plugin/data/kibana/data.plugin.js:1:361224 at async index…

---

## [Detector field "beat.hostname" is not an aggregatable field](https://discuss.elastic.co/t/detector-field-beat-hostname-is-not-an-aggregatable-field/287212)

<div class="topic-metadata">

**Author:** [@Mark3](https://discuss.elastic.co/u/Mark3)\
**Replies:** 1\
**Last updated:** [October 26, 2021, 11:00am UTC](https://discuss.elastic.co/t/detector-field-beat-hostname-is-not-an-aggregatable-field/287212 "2021-10-26T11:00:47Z")

</div>

Following the instructions for the DETECT DNS DATA EXFILTRATION lab, I hit this wall, any ideas? Cheers, Mark

---

## [Matching rule with indicator match error parsing date field](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [October 21, 2021, 3:16pm UTC](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171 "2021-10-21T15:16:01Z")

</div>

I create a index that contain all domain that i want to query to according to ecs. Now i create a rule that will match any domain query from dns index but it give me this errror: An error occurred during rule execution…

---

## [Security Detection Rules Cause: \`circuit\_breaking\_exception\` on medium-ish deployments](https://discuss.elastic.co/t/security-detection-rules-cause-circuit-breaking-exception-on-medium-ish-deployments/286654)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 6\
**Last updated:** [October 19, 2021, 12:51pm UTC](https://discuss.elastic.co/t/security-detection-rules-cause-circuit-breaking-exception-on-medium-ish-deployments/286654 "2021-10-19T12:51:53Z")

</div>

Hi All, I noticed that a few detection rules consume a lot of memory, and cause circuit\_breaking\_exception often in medium-ish deployments (~265 winlogbeat deployments). Elasticsearch version: 7.14.1 Offending Rules: …

---

## [EQL query help](https://discuss.elastic.co/t/eql-query-help/286974)

<div class="topic-metadata">

**Author:** [@Billz1026](https://discuss.elastic.co/u/Billz1026)\
**Replies:** 0\
**Last updated:** [October 18, 2021, 10:35am UTC](https://discuss.elastic.co/t/eql-query-help/286974 "2021-10-18T10:35:46Z")

</div>

Hi All, I am using EQL to write detection rues. I have a sequence of evens as follows. Event A Event B Event C I want to raise an alert if the time between Event A and Event C exceeds 30 seconds. I tried with maxspa…

---

## [How do I troubleshoot elastic agent not sending any logs to siem app](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 5\
**Last updated:** [October 12, 2021, 11:39am UTC](https://discuss.elastic.co/t/how-do-i-troubleshoot-elastic-agent-not-sending-any-logs-to-siem-app/286311 "2021-10-12T11:39:55Z")

</div>

Hi Team, I have enrolled windows serves through fleet and installed elastic-agent on them with malware-protction enabled in detect mode. However not a single log is being shipped hence wondering how do I troubleshoot th…

---

## [Fleet server agent unable to start- Connection refused](https://discuss.elastic.co/t/fleet-server-agent-unable-to-start-connection-refused/285818)

<div class="topic-metadata">

**Author:** [@Psyhil](https://discuss.elastic.co/u/Psyhil)\
**Replies:** 3\
**Last updated:** [October 7, 2021, 3:27pm UTC](https://discuss.elastic.co/t/fleet-server-agent-unable-to-start-connection-refused/285818 "2021-10-07T15:27:09Z")

</div>

Hi there, I have ELK running and am trying to test out Fleet and endpoint agent. To perform the test, I used the quick start deployment mode using self-signed certificate. However when trying to install the agent on a…

---

## [Machine Learning](https://discuss.elastic.co/t/machine-learning/285987)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 2\
**Last updated:** [October 7, 2021, 1:13pm UTC](https://discuss.elastic.co/t/machine-learning/285987 "2021-10-07T13:13:21Z")

</div>

Good Morning, Ran into a weird use case and wondering if anyone has suggestions. We have a couple thousand endpoints sending winlogbeats to our cluster, and we are trying to provide some kind of visibility into uptime o…

---

## [False Positives in the 1000's](https://discuss.elastic.co/t/false-positives-in-the-1000s/285019)

<div class="topic-metadata">

**Author:** [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Replies:** 1\
**Last updated:** [September 23, 2021, 11:31pm UTC](https://discuss.elastic.co/t/false-positives-in-the-1000s/285019 "2021-09-23T23:31:55Z")

</div>

Has anyone noticed a "HUGE" amount of false positives that occur when enabling the Detection Rule \[Threat Intel Filebeat Module Indicator Match\]. This rule is tagged as follows Continuous Monitoring Elastic Elastic E…

---

## [Single behavior generates several alerts](https://discuss.elastic.co/t/single-behavior-generates-several-alerts/283943)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 3\
**Last updated:** [September 21, 2021, 12:15pm UTC](https://discuss.elastic.co/t/single-behavior-generates-several-alerts/283943 "2021-09-21T12:15:54Z")

</div>

Hello evry body, I have a lot of alerts generated by a single behavior scan from the address IP x.x.x.x to the ip address Y (each time the rule is executed another alerts is created). Is there a way to have only one ale…

---

## [Threat intel integration](https://discuss.elastic.co/t/threat-intel-integration/282663)

<div class="topic-metadata">

**Author:** [@tejas.tech](https://discuss.elastic.co/u/tejas.tech)\
**Replies:** 3\
**Last updated:** [September 15, 2021, 1:05pm UTC](https://discuss.elastic.co/t/threat-intel-integration/282663 "2021-09-15T13:05:38Z")

</div>

Team, I have installed Filebeat 7.14.X agent and have enabled the threatintel module but unable to get feeds from all the threat intel. Could you please help us out on this?

---

## [Looking for a list of "Out of the Box" Use Cases for Elastic SIEM](https://discuss.elastic.co/t/looking-for-a-list-of-out-of-the-box-use-cases-for-elastic-siem/284101)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 1\
**Last updated:** [September 13, 2021, 4:34pm UTC](https://discuss.elastic.co/t/looking-for-a-list-of-out-of-the-box-use-cases-for-elastic-siem/284101 "2021-09-13T16:34:18Z")

</div>

I am working on a secure project that is utilizing ELK SIEM and we are looking for Use Cases that we can direct the client towards for answering what the Elastic SIEM can do for them. Is there a link or area that I can …

---

## [Run Elastic detection rule in non real time logs](https://discuss.elastic.co/t/run-elastic-detection-rule-in-non-real-time-logs/283787)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 1\
**Last updated:** [September 11, 2021, 1:15pm UTC](https://discuss.elastic.co/t/run-elastic-detection-rule-in-non-real-time-logs/283787 "2021-09-11T13:15:22Z")

</div>

Hello, I have some windows log files and I have uploaded them to my cluster using winlogbeat \[Not sure how to read from .evtx files | Winlogbeat Reference \[master\] | Elastic\] I would like to know if it's possible to ru…

---

## [Packetbeat 7.14.1 process.env not added to the document](https://discuss.elastic.co/t/packetbeat-7-14-1-process-env-not-added-to-the-document/283698)

<div class="topic-metadata">

**Author:** [@Rodrigo\_Bernardo](https://discuss.elastic.co/u/Rodrigo_Bernardo)\
**Replies:** 0\
**Last updated:** [September 8, 2021, 5:09pm UTC](https://discuss.elastic.co/t/packetbeat-7-14-1-process-env-not-added-to-the-document/283698 "2021-09-08T17:09:24Z")

</div>

Hello there, I tried to follow the documentation but with no success. Am I doing something wrong or packetbeat has issues sending the process environment into the document. I am using the latest version of packetbeat 7.…

---

## [Find exceptions in indices](https://discuss.elastic.co/t/find-exceptions-in-indices/283656)

<div class="topic-metadata">

**Author:** [@bil\_15](https://discuss.elastic.co/u/bil_15)\
**Replies:** 0\
**Last updated:** [September 8, 2021, 12:49pm UTC](https://discuss.elastic.co/t/find-exceptions-in-indices/283656 "2021-09-08T12:49:50Z")

</div>

Hello! I've created exception on the rule and interested in the way it works. For ex, in Splunk we're receiving suppressed events anyway, so they are still stored in appropriate index, but they are don't visible in SIE…

---

## [Threshold Rule type - not able to send more than three field values in email action](https://discuss.elastic.co/t/threshold-rule-type-not-able-to-send-more-than-three-field-values-in-email-action/283525)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 0\
**Last updated:** [September 7, 2021, 12:02pm UTC](https://discuss.elastic.co/t/threshold-rule-type-not-able-to-send-more-than-three-field-values-in-email-action/283525 "2021-09-07T12:02:44Z")

</div>

Continuing the discussion from Threshold Rule type - not able to send more than three field values in email action: Waiting for a reply for this issue.

---

## [Watch configuration (advance watch - Jason queries for cyber security)](https://discuss.elastic.co/t/watch-configuration-advance-watch-jason-queries-for-cyber-security/274632)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 4\
**Last updated:** [August 31, 2021, 1:52am UTC](https://discuss.elastic.co/t/watch-configuration-advance-watch-jason-queries-for-cyber-security/274632 "2021-08-31T01:52:57Z")

</div>

Good morning everyone, I have recently setup ELK with elastic on cloud and I am in the process of configuring watch. I want to mainly use this to monitor my environment from suspicious events like: new user created, 5-1…

---

## [Reduce duplicate signals/ alerts](https://discuss.elastic.co/t/reduce-duplicate-signals-alerts/282768)

<div class="topic-metadata">

**Author:** [@jaspher](https://discuss.elastic.co/u/jaspher)\
**Replies:** 0\
**Last updated:** [August 29, 2021, 10:23pm UTC](https://discuss.elastic.co/t/reduce-duplicate-signals-alerts/282768 "2021-08-29T22:23:10Z")

</div>

Hi, Is it possible to mute/ ignore repeating alerts for a period of time? For example, if a c2 beacon is detected, an alert does not need to be generated again if the signal is still open/ not closed. In Alienvault, t…

---

## [Common File for adding email address in SIEM Detection email action](https://discuss.elastic.co/t/common-file-for-adding-email-address-in-siem-detection-email-action/282341)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 1\
**Last updated:** [August 29, 2021, 8:58am UTC](https://discuss.elastic.co/t/common-file-for-adding-email-address-in-siem-detection-email-action/282341 "2021-08-29T08:58:48Z")

</div>

Hi, Please share if there any way to keep common file for Email "To" address and use parameter in detection email action instead of adding email address in each Detections Rules. I am using ELK 7.13.4. Thanks in adva…

---

## [Will elastic agent support more beats in future?](https://discuss.elastic.co/t/will-elastic-agent-support-more-beats-in-future/282291)

<div class="topic-metadata">

**Author:** [@spzala](https://discuss.elastic.co/u/spzala)\
**Replies:** 2\
**Last updated:** [August 24, 2021, 5:47am UTC](https://discuss.elastic.co/t/will-elastic-agent-support-more-beats-in-future/282291 "2021-08-24T05:47:51Z")

</div>

We are planning to use Elastic agent and fleet in one of the workflows. So, are there any possibilities that elastic agent and fleet may include more beats like a packetbeat in future releases? OR what's the road map of …

[Previous page](https://discuss.elastic.co/c/security/siem/78.md?page=8)

[Next page](https://discuss.elastic.co/c/security/siem/78.md?page=10)
