|
Sharing my rule update experience on Elastic Security Serverless
|
|
12
|
289
|
September 3, 2026
|
|
Threat Intel and SIEM
|
|
2
|
4459
|
November 17, 2020
|
|
Elastic SIEM TheHive Integration
|
|
1
|
2553
|
August 10, 2021
|
|
[ Creating new rule ]: ERROR Authentication using apikey failed - api key has been invalidated
|
|
4
|
9569
|
January 19, 2021
|
|
Palo Alto [SIEM]
|
|
2
|
728
|
June 19, 2020
|
|
Best way to analyze Event Correlation Sequence detections
|
|
5
|
2391
|
December 7, 2022
|
|
SIgma rules for Elastic SIEM
|
|
4
|
13241
|
April 3, 2021
|
|
Detecting inactive users in Active Directory
|
|
5
|
1810
|
January 25, 2023
|
|
Active Directory logs and mapping to ECS (I am stumped)
|
|
6
|
8742
|
October 14, 2019
|
|
Creating a case for an alert automatically
|
|
2
|
1686
|
January 27, 2022
|
|
Limit CPU/Memory usage in Auditbeat & Filebeats , version 7.9.0
|
|
7
|
5441
|
September 17, 2020
|
|
Multiple Different Clients
|
|
4
|
2048
|
January 4, 2021
|
|
Event Correlation on ELK
|
|
2
|
7980
|
August 26, 2019
|
|
Can I still use Threat Intelligence?
|
|
6
|
821
|
November 29, 2022
|
|
Feature Request for more robust vector graphics (Vega not enough) so I can generate good looking network maps (non-geographic)
|
|
2
|
624
|
March 23, 2023
|
|
Import rules from public detection rules repo
|
|
2
|
1953
|
August 18, 2020
|
|
Hosts table : host.name (alias of beat.name) used instead of agent.hostname
|
|
1
|
3963
|
February 17, 2020
|
|
Seperate email alerts per detection?
|
|
2
|
558
|
May 17, 2022
|
|
Fleet server agent unable to start- Connection refused
|
|
3
|
4680
|
October 7, 2021
|
|
"Machine learning permission error" for demo user
|
|
1
|
1158
|
June 25, 2020
|
|
Filebeat for Sophos XG Firewall
|
|
8
|
3041
|
August 7, 2019
|
|
Hosts duplicated with and without fqdn
|
|
6
|
1916
|
June 30, 2020
|
|
SIEM ECS descriptions taking huge amount of unneccesary space in SIEM
|
|
1
|
624
|
September 27, 2019
|
|
Config alerts and actions email connector
|
|
7
|
2906
|
September 24, 2020
|
|
SOAR for elk
|
|
2
|
4657
|
April 16, 2020
|
|
Aggregation support in SIEM
|
|
2
|
792
|
June 23, 2020
|
|
SIEM feature request
|
|
4
|
612
|
October 1, 2020
|
|
Alert when an event is not followed by another
|
|
6
|
913
|
September 26, 2022
|
|
How to define time range in custom query rule in elasticsiem?
|
|
5
|
1747
|
March 23, 2021
|
|
Bulk indexing of signals failed in Kibana 7.10.2
|
|
7
|
2673
|
January 29, 2021
|
|
WHAT SIEM CAN DO?
|
|
3
|
1185
|
August 13, 2020
|
|
Unifi Ubiquity USG IPS Suricata Filebeat Logging
|
|
2
|
1349
|
May 14, 2020
|
|
Signal - multiple login failure from same user
|
|
1
|
1648
|
November 16, 2020
|
|
Building block rules/use case
|
|
7
|
2599
|
November 10, 2020
|
|
Sending the alert JSON details using Webhook Connector
|
|
7
|
1450
|
April 11, 2024
|
|
Detection rule: Failed login attempts
|
|
2
|
3986
|
June 2, 2021
|
|
Host not showing up despite events being present
|
|
8
|
2285
|
March 13, 2020
|
|
SIEM Threshold - unique values
|
|
5
|
1533
|
September 1, 2020
|
|
Security rules failing (timed out) all the time
|
|
5
|
2720
|
November 1, 2021
|
|
"path: /_security/api_key... api keys are not enabled" while loading prebuilt detection rules
|
|
3
|
3309
|
February 16, 2020
|
|
Creating a rule exception
|
|
1
|
1468
|
July 21, 2022
|
|
Graylog logs directed to Elastic SIEM
|
|
5
|
2661
|
June 1, 2020
|
|
Another Feature Request for SIEM
|
|
5
|
832
|
July 8, 2020
|
|
Shards failed warning on Network dashboard in SIEM app
|
|
8
|
2134
|
March 3, 2020
|
|
How to create a rule with aggregation
|
|
4
|
2837
|
April 6, 2021
|
|
Elastic SIEM for MSSP
|
|
6
|
2389
|
June 11, 2020
|
|
Shodan Integration
|
|
4
|
2752
|
April 1, 2020
|
|
Adding Fleet Server failed because “x509: certificate signed by unknown authority“
|
|
5
|
2486
|
January 30, 2023
|
|
SSH auth logs not visualized in Kibana
|
|
5
|
2480
|
May 19, 2020
|
|
Run Elastic detection rule in non real time logs
|
|
1
|
764
|
September 11, 2021
|