# Adding user.name as a pivot item

**URL:** <https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863>\
**Category:** SIEM\
**Created:** [June 19, 2020, 8:03pm UTC](https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863 "2020-06-19T20:03:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![forkhead](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forkhead/32/46108_2.png) [@forkhead](https://discuss.elastic.co/u/forkhead)\
**Post date:** [June 19, 2020, 8:03pm UTC](https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863/1 "2020-06-19T20:03:26Z")

</div>

Hi, I am playing around with SIEM app and was wondering if there is a way to pivot off of user.name rather than Hosts and IP. I understand I can use Events and filter for both user.name and host.name but might be helpful in cases where the log/event itself is not tied to a specific host but to a user.

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [June 23, 2020, 12:49pm UTC](https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863/2 "2020-06-23T12:49:41Z")

</div>

@forkhead, welcome to our forum, and thanks for the question!

The general answer is that yes, we agree, being able to pivot off the username is a very useful capability for security analysts.

I'm not sure I fully understand your question about "where" in the app you want to pivot. Maybe you are looking for a "Users" page to complement the existing "Hosts" page? If so, yes, this is on our future capabilities list.

In the meantime, please let me explore this approach to pivoting in the SIEM app to see if it can help.

Using the SIEM app, in the Timeline event viewer, you can use any ECS-compatible `field:value` filter to pivot across all your siem-related data. By default, the timeline will search all your indices that are specified in your `siem:defaultIndex` advanced setting. So simply dragging a `user.name:value` filter to the drop area, you are automatically able to pivot across all your data.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/b/6bdd6a19b4e186e0c5399d31fa0dbdb7ff460742.png)

Would love to hear your further thoughts.

Thanks!

---

<div class="post-metadata">

**Author:** ![forkhead](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forkhead/32/46108_2.png) [@forkhead](https://discuss.elastic.co/u/forkhead)\
**Post date:** [June 23, 2020, 5:00pm UTC](https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863/3 "2020-06-23T17:00:07Z")

</div>

@Mike_Paquette Exactly, I was looking for a "Users" page like the existing "Hosts" page. Timeline is pretty cool and the ways it can be used, yes I am using Timeline to see all the events for the host.name and user.name. Not sure if Elastic Security has plans for adding UEBA functionalities to it. Thanks for the information and all the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2020, 5:00pm UTC](https://discuss.elastic.co/t/adding-user-name-as-a-pivot-item/237863/4 "2020-07-21T17:00:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
