# 7.6.0 vs new signals and futher enrich ingestion

**URL:** <https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211>\
**Category:** SIEM\
**Created:** [February 13, 2020, 1:33pm UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211 "2020-02-13T13:33:38Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [February 13, 2020, 1:33pm UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/1 "2020-02-13T13:33:38Z")

</div>

Just updated our cluster to 7.6.0 and are wondering where to read up on utilizing the new SIEM signals and if needed how to do further ingestion enriching to enhance signals eta.

Currently got winlog(+sysmon) and audit beat data ingesting from Windows Assets enriching with geo data in ingest pipelines.

TIA

Signals view from SIEM overview page seems to not known about which indices to look in:

 ![Screenshot 2020-02-13 at 14.25.52](https://us1.discourse-cdn.com/elastic/original/3X/b/a/ba721cd32c2521c6c88d6053b084889c9295c54c.png)

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [February 13, 2020, 3:31pm UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/2 "2020-02-13T15:31:21Z")

</div>

Hi stefws,

Thanks for the screenshot. That is looking like an interaction bug somewhere we have. We create the siem signals index when you first click the detections tab and then navigate to the "manage signal detection" page by clicking the button.

That should hopefully make things right and only a one time thing. I think we just forgot one or two first time visiting places to initialize it (such as that page) as a lot of people were working on things concurrently during the development cycle and what you're seeing is a bug.

 ![Screen Shot 2020-02-13 at 8.29.11 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d92d3100241b78d4590cdd5ad0b9c96a5ff14bb6.png)

For docs, we have a lot here at the moment that hopefully helps you out:  
[https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html](https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html)

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [February 14, 2020, 12:46am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/3 "2020-02-14T00:46:44Z")

</div>

I have been able to reproduce it and this should be just a one time issue you're seeing on first page loads until you make your way to the "manage signal detection rules" page where it will initialize the siem signals index.

Issue if you want to track it:

> <https://github.com/elastic/kibana/issues/57641>
>
> Describe the bug:
> Users checking their inspect signals requests are seeing that it is has errors.
> Inspect Signals when the index does not...

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [February 14, 2020, 9:27am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/4 "2020-02-14T09:27:02Z")

</div>

Right thanks, assume it requires a License, currently still only on Basic License 😕

Will dig into doc link...

 ![Screenshot 2020-02-14 at 10.25.12](https://us1.discourse-cdn.com/elastic/original/3X/9/8/9833abb3f3cba56a62d7bfc8d9873f4b10c26880.png)

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [February 14, 2020, 9:36am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/5 "2020-02-14T09:36:28Z")

</div>

Ah I need further permission properly to enter Detections... only in order to be able to launch 7.6.0 kibana I needed to removed this config key:

```
#7.6.0 dont like this key#xpack.encrypted_saved_objects.encryptionKey: <redacted>

```

otherwise kibana would start 😕 Get this error on launch with encryptionKey defined:

```
tail -f /var/log/kibana/kibana.log:
...
{"type":"log","@timestamp":"2020-02-14T09:40:01Z","tags":["info","plugins-service"],"pid":16961,"message":"Plugin \"case\" is disabled."}
{"type":"log","@timestamp":"2020-02-14T09:40:05Z","tags":["warning","legacy-plugins"],"pid":16961,"path":"/usr/share/kibana/src/legacy/core_plugins/expressions","message":"Skipping non-plugin directory at /usr/share/kibana/src/legacy/core_plugins/expressions"}
{"type":"log","@timestamp":"2020-02-14T09:40:05Z","tags":["warning","legacy-plugins"],"pid":16961,"path":"/usr/share/kibana/src/legacy/core_plugins/kbn_doc_views","message":"Skipping non-plugin directory at /usr/share/kibana/src/legacy/core_plugins/kbn_doc_views"}
{"type":"log","@timestamp":"2020-02-14T09:40:05Z","tags":["warning","legacy-plugins"],"pid":16961,"path":"/usr/share/kibana/src/legacy/core_plugins/metrics","message":"Skipping non-plugin directory at /usr/share/kibana/src/legacy/core_plugins/metrics"}
^C
[root@kibana6 ~]# tail /var/log/messages
Feb 14 10:40:06 kibana6 kibana: FATAL Error: Unknown configuration key(s): "xpack.encrypted_saved_objects.encryptionKey". Check for spelling errors and ensure that expected plugins are installed.
Feb 14 10:40:07 kibana6 systemd: kibana.service: main process exited, code=exited, status=64/n/a
Feb 14 10:40:07 kibana6 systemd: Unit kibana.service entered failed state.
Feb 14 10:40:07 kibana6 systemd: kibana.service failed.
```

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [February 14, 2020, 9:46am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/6 "2020-02-14T09:46:51Z")

</div>

Ah spelled differently xpack.encryptedSavedObjects.encryptionKey, this works to launch kibana at least, will investigate permissions further...

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [February 14, 2020, 10:03am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/7 "2020-02-14T10:03:05Z")

</div>

Okay, then it created the .siem-signals-\<space\> index but to be able to load rules it seems I need to enable API keys:

```
{"type":"log","@timestamp":"2020-02-14T09:52:32Z","tags":["error","plugins","security","api-key"],"pid":17120,"message":"Failed to create API key: [illegal_state_exception] api keys are not enabled"}
{"type":"error","@timestamp":"2020-02-14T09:52:32Z","tags":[],"pid":17120,"level":"error","error":{"message":"[illegal_state_exception] api keys are not enabled","name":"Error","stack":"Error: [illegal_state_exception] api keys are not enabled\n at transformError (/usr/share/kibana/x-pack/legacy/plugins/siem/server/lib/detection_engine/routes/utils.js:24:14)\n at handler (/usr/share/kibana/x-pack/legacy/plugins/siem/server/lib/detection_engine/routes/rules/add_prepackaged_rules_route.js:84:16)\n at process._tickCallback (internal/process/next_tick.js:68:7)"},"url":{"protocol":null,"slashes":null,"auth":null,"host":null,"port":null,"hostname":null,"hash":null,"search":null,"query":{},"pathname":"/api/detection_engine/rules/prepackaged","path":"/api/detection_engine/rules/prepackaged","href":"/api/detection_engine/rules/prepackaged"},"message":"[illegal_state_exception] api keys are not enabled"}
```

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [February 14, 2020, 3:01pm UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/8 "2020-02-14T15:01:22Z")

</div>

Okay, this took me most of today to convert http to https for all Elastic Clients (kibana/grafana/log stash/beat instances) in our production cluster. Will dig further next week on how to activate the API-key API...

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [February 14, 2020, 4:35pm UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/9 "2020-02-14T16:35:06Z")

</div>

Yeah,

Glad you got through most of that. The cloud deployments are all configured with security in mind and so that is honestly the easiest way to get and stay setup for the Elastic Stack. Nothing wrong with on prem deployments, just mentioning the cloud deployment self managed model does the configuration steps automatically since it is already behind things like https.

The https/TLS, API Key setup, and encryption key setup should hopefully make sense as when you are creating SIEM rules and they run even when you are no longer logged in they use API Keys under the covers. Because it uses that mechanism it is going to need the other security mechanism turned on.

This part of the docs might help out more where it explains more in depth parts of permissioning:  
[https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#detections-permissions](https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#detections-permissions)

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [February 17, 2020, 8:14am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/10 "2020-02-17T08:14:17Z")

</div>

Okay, after converting to https between all cluster-internally elastic clients (externals clients was/are terminating TLS on a HAproxy cluster, load balancing across ingest/logstash nodes) and our elastic cluster. I now could load the 92 elastic signal detection rules, which each created their own never-expiring API key 🙂

Thanks, will read up on the detection engine to understand it's inner workings better...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2020, 6:12am UTC](https://discuss.elastic.co/t/7-6-0-vs-new-signals-and-futher-enrich-ingestion/219211/13 "2020-04-06T06:12:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
