# Elastic SIEM alerts + auditbeats - only few are working fine

**URL:** <https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [February 1, 2021, 9:26am UTC](https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810 "2021-02-01T09:26:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Orion](https://avatars.discourse-cdn.com/v4/letter/o/a88e4f/32.png) [@Orion](https://discuss.elastic.co/u/Orion)\
**Post date:** [February 1, 2021, 9:26am UTC](https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810/1 "2021-02-01T09:26:03Z")

</div>

Hello,  
first post in the forum, since using free Elastic licence, would like to seek for some support in the discussion board. Currently I'm experimenting on SIEM \> Detections module, have Elastic stack installed on one computer, Auditbeat on another, and for example when running nmap, base64 encoding decoding alert is generated in SIEM \> Detections, but for example another ones, like nping, mknod etc. never generated an alert, but it's visible in elastic when looking at auditbeat logs. For experiment sake I have enabled all the 149 rules which was preconfigured, but only few of them are working. Any suggestions what am I doing wrong?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 1, 2021, 12:25pm UTC](https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810/2 "2021-02-01T12:25:03Z")

</div>

Please share your [all your debug logs of Auditbeat](https://www.elastic.co/guide/en/beats/auditbeat/current/enable-auditbeat-debugging.html) and the configuration formatted using `</>`?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 1, 2021, 8:16pm UTC](https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810/3 "2021-02-01T20:16:21Z")

</div>

The base64 detection query is:

> <https://github.com/elastic/detection-rules/blob/e272800a5d54803c48d83027424ca5e28825ab4f/rules/linux/defense_evasion_base64_encoding_or_decoding_activity.toml#L27-L28>

Can you share the raw event for the base64 process that Auditbeat sent to Elasticsearch? Then we can see if there's something that would cause the query to not match. The only other issue I can think of would be timing (like the event wasn't in Elasticsearch when the rule executed its query).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2021, 10:16pm UTC](https://discuss.elastic.co/t/elastic-siem-alerts-auditbeats-only-few-are-working-fine/262810/4 "2021-03-01T22:16:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
