I have been playing with ELK for a month now, and I want to setup alerting rules based on failed attempts or so. For now, I have only found ElastAlert on github.
Recently, I heard that there is a new functioality which is SIEM.
I tried to works with it but I was not able to get any data in SIEM. However, I can see data in Discover! I tried using the elasticsearch filebeat module.
Do I need to disable logstash ? Only filebeat -> elasticsearch -> kibana ?
Any hint is welcome!