|
Webhook - Case Management connector JSON payload from case object variables
|
|
0
|
258
|
March 8, 2024
|
|
Adding alers to cases in bulk
|
|
1
|
182
|
May 15, 2024
|
|
Add additional data source to SIEM dashboard
|
|
3
|
722
|
September 18, 2019
|
|
Adding a condition in detection engine
|
|
1
|
1014
|
April 10, 2020
|
|
Send Linux/Windows/NetworkDevices logs to Elastic SIEM
|
|
1
|
1008
|
June 26, 2020
|
|
Can Someone Help me Configure Suricata Filebeat on elastic cloud?
|
|
1
|
1004
|
November 21, 2019
|
|
SIEM Event Correlation rule returns no data
|
|
3
|
709
|
December 17, 2021
|
|
Just a question about a siem rule filter
|
|
3
|
709
|
November 30, 2020
|
|
Elastic Security Rule exception
|
|
1
|
999
|
March 22, 2022
|
|
PoC - Use ELK to aggregate multiple LogInsight Systems into one SOC
|
|
2
|
793
|
September 3, 2019
|
|
Email Action for Detection Rule
|
|
2
|
791
|
April 15, 2021
|
|
Can Elastic SIEM have a Group By feature in the Timelines?
|
|
4
|
610
|
May 15, 2020
|
|
Aggregating Case Information
|
|
4
|
608
|
January 14, 2022
|
|
EQL - Rule creation
|
|
1
|
539
|
August 31, 2022
|
|
Winlogbeat 7.9 not shipping logs in full ECS?
|
|
3
|
669
|
September 24, 2020
|
|
{{#context.alerts}} not showing up in markdown
|
|
2
|
772
|
June 16, 2021
|
|
Unusual Process For a Windows Host (rare_process_by_host_windows_ecs)
|
|
4
|
596
|
July 1, 2021
|
|
Rules in ElasticSIEM not create signals
|
|
4
|
586
|
April 16, 2020
|
|
Update detection rules from elastic github repository to on-premises
|
|
2
|
756
|
August 4, 2020
|
|
D365 cloud based solution
|
|
1
|
517
|
February 19, 2021
|
|
Can I change the primary key for identifying hosts in the SIEM app?
|
|
3
|
648
|
August 4, 2020
|
|
Watch configuration (advance watch - Jason queries for cyber security)
|
|
4
|
562
|
August 31, 2021
|
|
Multiple index search
|
|
5
|
513
|
April 3, 2023
|
|
Detection Rule Key Value Reference Url's
|
|
5
|
511
|
May 22, 2021
|
|
EQL rules do not work but see hits
|
|
2
|
719
|
February 14, 2022
|
|
Unable to start audit beat
|
|
0
|
1242
|
November 27, 2019
|
|
Elastic SIEM - Adding more data
|
|
1
|
878
|
December 17, 2019
|
|
Threat hunting with suricata, ElasticSecurity
|
|
1
|
864
|
May 17, 2021
|
|
Detection not finding anything but same query finds them
|
|
5
|
495
|
February 27, 2021
|
|
Exceptions in rules through DaC
|
|
2
|
123
|
February 9, 2026
|
|
Fielddata error preventing Authentications tab populating
|
|
3
|
599
|
September 4, 2019
|
|
How to change query in SIEM
|
|
2
|
689
|
October 21, 2019
|
|
Elastic Search not work with evebox
|
|
5
|
486
|
March 14, 2024
|
|
Reporting email action failure from watcher - ELK7.8
|
|
2
|
683
|
March 18, 2021
|
|
Edit Telnet port Activity rule
|
|
2
|
679
|
March 22, 2021
|
|
Last Seen timestamp under Hosts section appears to be incorrect
|
|
2
|
674
|
July 11, 2019
|
|
Siem anomaly detection prebuild jobs
|
|
1
|
822
|
January 2, 2020
|
|
SIEM Overview Page : Modify Security Settings Kibana
|
|
4
|
519
|
August 10, 2020
|
|
Rule failure for Windows path exclusions?
|
|
4
|
517
|
December 9, 2020
|
|
Elastic Detection Actions - any way to add fields?
|
|
1
|
457
|
March 28, 2022
|
|
Auditing all Linux clients with centralised server
|
|
3
|
570
|
July 10, 2021
|
|
Security events and rules matching
|
|
2
|
655
|
July 26, 2022
|
|
Viewing Pinned Timeline Events
|
|
1
|
799
|
October 25, 2019
|
|
Cloudflare integration Logpull not working
|
|
2
|
651
|
June 1, 2022
|
|
Signal SIEM Detections using log files
|
|
4
|
504
|
April 25, 2020
|
|
Rules failing
|
|
2
|
650
|
December 18, 2023
|
|
[SIEM] Authentications table doesn't show 'Last Success/Failed Source' column if only 'source.ip' is present
|
|
6
|
423
|
January 19, 2021
|
|
Auditbeat docker (7.4.2) starts and then terminates with no error
|
|
1
|
791
|
November 26, 2019
|
|
SIEM feature request
|
|
3
|
559
|
November 10, 2020
|
|
Zeek filebeat - HTTP and TLS events not fully populating
|
|
3
|
553
|
April 11, 2020
|