I have a problems in the elastic siem.
The filter function for me when i tried to filter for some field in the rule that i have created. those field seems to be not recognized by elastic so they do not allow me to filter those data. event though i have tried to create the index pattern and still the data is not recognized.
Is there a way to make siem understand those data since i really need to filter those data out.
Thanks for your time.