# Elasticsearch SIEM is not working, but EQL query is ok

**URL:** <https://discuss.elastic.co/t/elasticsearch-siem-is-not-working-but-eql-query-is-ok/287590>\
**Category:** SIEM\
**Tags:** docker\
**Created:** [October 25, 2021, 2:38pm UTC](https://discuss.elastic.co/t/elasticsearch-siem-is-not-working-but-eql-query-is-ok/287590 "2021-10-25T14:38:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dalador](https://avatars.discourse-cdn.com/v4/letter/d/a9a28c/32.png) [@Dalador](https://discuss.elastic.co/u/Dalador)\
**Post date:** [October 25, 2021, 2:38pm UTC](https://discuss.elastic.co/t/elasticsearch-siem-is-not-working-but-eql-query-is-ok/287590/1 "2021-10-25T14:38:36Z")

</div>

I got some problems with my ELK running on docker. I made ssl on tls and http and tryied to make simple EQL-query:

```auto
sequence by winlog.computer_name 
[iam where event.code == "4720"] 
[iam where event.code == "4726"]

```

When i click on show results i see hits:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df4fa5866941fb15e9d6a947063936a1157f20ee.png)

but when i'm trying to reproduce alert it's zero hits in index:  
`.siem-signals-default-*`

I got some warns from my Elasticsearch-container:

```auto
{"type": "server", "timestamp": "2021-10-25T12:37:33,433Z", "level": "WARN", "component": "o.e.x.s.t.n.SecurityNetty4HttpServerTransport", "cluster.name": "elastdocker-cluster", "node.name": "elastdocker-node-0", "message": "received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=/172.20.0.5:9200, remoteAddress=/172.20.0.2:43450}", "cluster.uuid": "oZsivcyzROWSooXVIPzbKQ", "node.id": "KIjWJ0OjSW-lYt51cO8ViQ" }

```

Where is the problem? Any ideas?

---

<div class="post-metadata">

**Author:** ![Dalador](https://avatars.discourse-cdn.com/v4/letter/d/a9a28c/32.png) [@Dalador](https://discuss.elastic.co/u/Dalador)\
**Post date:** [October 29, 2021, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-siem-is-not-working-but-eql-query-is-ok/287590/2 "2021-10-29T13:54:11Z")

</div>

This helps:

```auto
PUT /_cluster/settings
{
  "persistent" : {
    "xpack" : {
      "monitoring" : {
        "migration" : {
          "decommission_alerts" : "true"
        }
      }
    }
  },
  "transient" : { }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2021, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-siem-is-not-working-but-eql-query-is-ok/287590/3 "2021-11-26T13:54:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
