# Filebeat as Datasource for Elastic SIEM

**URL:** <https://discuss.elastic.co/t/filebeat-as-datasource-for-elastic-siem/239756>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 3, 2020, 8:42am UTC](https://discuss.elastic.co/t/filebeat-as-datasource-for-elastic-siem/239756 "2020-07-03T08:42:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![robincher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robincher/32/41282_2.png) [@robincher](https://discuss.elastic.co/u/robincher)\
**Post date:** [July 3, 2020, 8:42am UTC](https://discuss.elastic.co/t/filebeat-as-datasource-for-elastic-siem/239756/1 "2020-07-03T08:42:23Z")

</div>

Hi ,

I am looking at piping logs for MS Azure AD to SIEM, specifically for _investigating attempted logins and related activity with authentication data gathered by Auditbeat and the Filebeat system modules._

From Kibana, i am unable to find sources for taking in Filebeat.

May i know if its possible for such set-up? I am using Elastic Cloud enterprise 7.8.

 ![Screenshot 2020-07-03 at 4.41.12 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6d25fa88fcf5475f01bb2f9b95684ab69db29e6.png)

Robin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2020, 10:46am UTC](https://discuss.elastic.co/t/filebeat-as-datasource-for-elastic-siem/239756/2 "2020-07-31T10:46:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
