# Graylog logs directed to Elastic SIEM

**URL:** <https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750>\
**Category:** SIEM\
**Created:** [May 28, 2020, 1:08pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750 "2020-05-28T13:08:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [May 28, 2020, 1:08pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750/1 "2020-05-28T13:08:17Z")

</div>

Hi people, I have a Graylog server fulfilled of a lot of network and host logs.

On the other hand, I have a new Elastic SIEM 7.7 implementation and some servers with different beats that point to it.

But I have to direct all Graylog logs to the Elastic SIEM, in order to fulfill this new systen and to have more security events detection and analisys capacity.

Is there any way to send all Gralog logs to my Elastic SIEM?

Thanks a lot !!!

---

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [May 28, 2020, 2:17pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750/2 "2020-05-28T14:17:00Z")

</div>

Please let me add:

In Graylog I can see two type of outoputs:

Standard and GELF (Graylog Extended Log Format).

In GELF output, I can define IP, Port and Protocol of destination SIEM server. When I did that I can see packets arriving to my SIEM, but I can't see them on the GUI.

Thanks again!!!

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 28, 2020, 7:14pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750/3 "2020-05-28T19:14:32Z")

</div>

Hey there Robert, thanks for writing in!

Good to hear you were able to export your data, now let's see what we can do to get it to start showing up within the SIEM App. 🙂

The first thing to check is that the data index you're sending your Graylog data to has been added to the `siem:defaultIndex` configuration setting under `Management` -\> `Kibana` -\> `Advanced Settings` -\> `SIEM`.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a8e0067a62d9689fc9ccae6ca2a78da4e46b4cf.png)

We've provided a few [default indices](https://www.elastic.co/guide/en/kibana/current/xpack-siem.html#_beats) that correspond to the common beats used with SIEM, but in order to leverage custom data you'll want to add your data indices to this setting. As shown, you can use globs to match multiple ES indices.

Once that's configured, the next thing to verify is that your data is in the correct format. The majority of the SIEM App and its visualizations rely on data following the [Elastic Common Schema (ECS)](https://www.elastic.co/guide/en/ecs/master/ecs-reference.html), as this enables us to reference a common field-set that can span many different data sources.

To ensure your data is being mapped to ECS, there's this wonderful [blog post](https://www.elastic.co/blog/getting-started-adding-new-security-data-source-in-elastic-siem) that outlines how to set things up either using beats, or for your case, how to add an ingest pipeline to convert fields to ECS using the [ecs-mapper tool](https://github.com/elastic/ecs-mapper).

Lastly, if you're curious why data isn't showing up in a particular visualization, you can use the inspect feature to see what index patterns are being queried, and more importantly, what _fields are required_.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a08110dee983b9124bd45e1847fc866df4f14681.png) ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/4/5426e54656c05eb7de10c11345258cb3f410f5a2.png)

Hopefully that provides some context for how to get your data showing up within the SIEM App, and if for some reason this doesn't resolve the issue you're seeing, feel free to respond back with details and we can dig a bit deeper!

Cheers! 🙂  
Garrett

---

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [May 29, 2020, 2:15pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750/4 "2020-05-29T14:15:09Z")

</div>

Dear Garret, thanks a lot for your relevant help.

Now I'll read in depth your message and I'll try to do what you say.

Please, if you can tell me this:

Do I have to create a new index for Graylog data in my Elastic SIEM, or the index will be created automatically when data arrive?

Thanks a lot again.

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 29, 2020, 9:21pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750/5 "2020-05-29T21:21:04Z")

</div>

So by default, if the index does not exist it'll be created automatically when putting data. This will create an index with a dynamic mapping though (so long as you don't have any index templates configured), so you'll want to watch out for that. You can read more about how [indices are created automatically here](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-index_.html#index-creation).

Depending on how you're ingesting your GELF output from Graylog, you might just be able to to use an `ingest pipeline` to convert your fields to ECS with the correct mapping. The [blog post linked above](https://www.elastic.co/blog/getting-started-adding-new-security-data-source-in-elastic-siem) goes into detail on getting that set up.

Hope that helps! 🙂  
Garrett

---

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [June 1, 2020, 12:32pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750/6 "2020-06-01T12:32:14Z")

</div>

Thanks a lot Garret, your comments are very helpful to me.

Regards!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2020, 12:32pm UTC](https://discuss.elastic.co/t/graylog-logs-directed-to-elastic-siem/234750/7 "2020-06-29T12:32:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
