# Can Elastic SIEM have a Group By feature in the Timelines?

**URL:** <https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725>\
**Category:** SIEM\
**Created:** [May 14, 2020, 11:41pm UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725 "2020-05-14T23:41:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilo21](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilo21/32/66272_2.png) [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Post date:** [May 14, 2020, 11:41pm UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725/1 "2020-05-14T23:41:42Z")

</div>

Hello,

When it comes to Elastic Stack is has great functionalities for specific detection trigerred by well tuned rules but security analysts struggle when it comes to generic checks like if I have a phishing related public IP that hosts a malware and i wanna see the list of source.ip and user.name that started a communication towards this IP, neither in the timeline or discovery panel I can see unique number of source.ip since i should scroll down pages and i might miss something. Even the unique values at the left panel in the Discovery page won't be enough.

My question is, is there a way to do this apart from creating aggregation (more queries and time consuming). Would it be such a feature in future releases ? why isn't up till now present in the SIEM APP ?

Thank you

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [May 15, 2020, 2:13am UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725/2 "2020-05-15T02:13:56Z")

</div>

Hi @hilo21, thanks for your post and for your interest in the SIEM app!

> [@hilo21](#):
>
> My question is, is there a way to do this apart from creating aggregation (more queries and time consuming).

We've actually got a whole slew of [threat hunting enhancements](https://github.com/elastic/kibana/pull/61207)) arriving in 7.8, and one in particular should address your use case: **Show top fields**.

The author does a great job detailing those features in the above link, so I definitely recommend checking that out! However, specific to your example of viewing unique `source.ip`s communicating with a malware host, within the SIEM app you'll be able to:

1. Build a timeline with `destination.ip: <malware_host>`
2. Hover `source.ip` (either in a row renderer or the column header)
3. Click "Show top source.ip" from the context menu

Which will then generate a histogram of the top `source.ip` values within that timeline, like so:

 ![Slack ___threat-hunting___ Elastic](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4febac215a927721ea6df360b63e788fd479a1f.png)

We hope this feature will help you and others to be even more effective in your threat hunting. Please do keep the feature requests coming, both here and on [GitHub](https://github.com/elastic/kibana/issues/new?template=Feature_request.md)!

(Edit: fixed "threat hunting enhancements" link above)

--  
Ryland

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [May 15, 2020, 1:19pm UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725/3 "2020-05-15T13:19:13Z")

</div>

Thanks @RylandHerrick for the great reply!!

Looks like this link isn't working:

> [@RylandHerrick](#):
>
> threat hunting enhancements

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [May 15, 2020, 1:53pm UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725/4 "2020-05-15T13:53:21Z")

</div>

Hey @ebeahan , good catch! I've updated my reply with the fix. Thanks!

---

<div class="post-metadata">

**Author:** ![hilo21](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilo21/32/66272_2.png) [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Post date:** [May 15, 2020, 10:00pm UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725/5 "2020-05-15T22:00:47Z")

</div>

@RylandHerrick Thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2020, 10:00pm UTC](https://discuss.elastic.co/t/can-elastic-siem-have-a-group-by-feature-in-the-timelines/232725/6 "2020-06-12T22:00:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
