Elastic siem overview dashboard config

Hello.
I recevied suricata and other security solution logs with filebeat and send to Elastic Siem

Is it possible to edit the list in the Network Event, Host Event menu in SIEM's Overview Tab??

I don't use Auditbeat and I don't want to see it.
Also, I would like to add the status of events of other security solutions that I am receiving with Filebeat.

I want to delete Cisco, Palo Alto, which is not even used by the filebeat of Network Events. I want to add something else.

You can change what indexes SIEM looks at from here:

This is global for the whole siem solution though.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.