# Detecting Exploitation of CVE-2021-44228 (log4j2) with Elastic Security

**URL:** <https://discuss.elastic.co/t/detecting-exploitation-of-cve-2021-44228-log4j2-with-elastic-security/292138>\
**Category:** Elastic Security\
**Created:** [December 16, 2021, 10:56am UTC](https://discuss.elastic.co/t/detecting-exploitation-of-cve-2021-44228-log4j2-with-elastic-security/292138 "2021-12-16T10:56:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jbal24](https://avatars.discourse-cdn.com/v4/letter/j/4491bb/32.png) [@jbal24](https://discuss.elastic.co/u/jbal24)\
**Post date:** [December 16, 2021, 10:56am UTC](https://discuss.elastic.co/t/detecting-exploitation-of-cve-2021-44228-log4j2-with-elastic-security/292138/1 "2021-12-16T10:56:35Z")

</div>

Hi everyone,

I would like to check with you one thing, we use our corporate Elastic as a SIEM using the security feature.

## We have seen this blog about: Detecting Exploitation of CVE-2021-44228 (log4j2) with Elastic Security

> **[Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security —...](https://www.elastic.co/security-labs/detecting-log4j2-with-elastic-security)**
>
> This blog post provides a summary of CVE-2021-44228 and provides Elastic Security users with detections to find active exploitation of the vulnerability in their environment. Further updates will be provided to this post as we learn more.

We are using filebeat and windlogsbeat to ingest elastic.

Do you know if it is possible for us to implement this detections rules or it needs another feature to configure these rules?

Like Endpoint security, Endgame, audit beat....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2022, 10:57am UTC](https://discuss.elastic.co/t/detecting-exploitation-of-cve-2021-44228-log4j2-with-elastic-security/292138/2 "2022-01-13T10:57:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
