# How to change query in SIEM

**URL:** <https://discuss.elastic.co/t/how-to-change-query-in-siem/204113>\
**Category:** SIEM\
**Created:** [October 17, 2019, 6:21pm UTC](https://discuss.elastic.co/t/how-to-change-query-in-siem/204113 "2019-10-17T18:21:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [October 17, 2019, 6:21pm UTC](https://discuss.elastic.co/t/how-to-change-query-in-siem/204113/1 "2019-10-17T18:21:13Z")

</div>

Im using Elastic stack 7.4 and stup auditbeat, filebeat, packetbeat ready.  
Im focus on SIEM -\> network, in Top DNS domains panel, i saw , default get top root domain not real domain. ( dns.question.registered\_domain instead of dns.question.name)

For example, server query domain [abc.xyz.com](http://abc.xyz.com). In Top DNS domains panel will show [xyz.com](http://xyz.com). It not good, When i use timeline, drag and drop [xyz.com](http://xyz.com), get many result, many event is unrelated. It can be list down [aaa.xyz.com](http://aaa.xyz.com), [bbb.xyz.com](http://bbb.xyz.com).

How to change query in SIEM panel ?  
Thank

```
{
  "aggregations": {
    "dns_count": {
      "cardinality": {
        "field": "dns.question.registered_domain"
      }
    },
    "dns_name_query_count": {
      "terms": {
        "field": "dns.question.registered_domain",
        "size": 10,
        "order": {
          "unique_domains": "desc"
        }
      },
      "aggs": {
        "unique_domains": {
          "cardinality": {
            "field": "dns.question.name"
          }
        },
        "dns_bytes_in": {
          "sum": {
            "field": "source.bytes"
          }
        },
        "dns_bytes_out": {
          "sum": {
            "field": "destination.bytes"
          }
        }
      }
    }
  },
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": 1571249363494,
              "lte": 1571335763494
            }
          }
        }
      ],
      "must_not": [
        {
          "term": {
            "dns.question.type": {
              "value": "PTR"
            }
          }
        }
      ]
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [October 18, 2019, 11:19am UTC](https://discuss.elastic.co/t/how-to-change-query-in-siem/204113/2 "2019-10-18T11:19:34Z")

</div>

Hi @tatdat, there currently is no way to change the queries used in the SIEM app. You could instead create a table visualization and view it on a dashboard, would that work?

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [October 21, 2019, 2:32am UTC](https://discuss.elastic.co/t/how-to-change-query-in-siem/204113/3 "2019-10-21T02:32:36Z")

</div>

I found solution. In timeline, select field need to search, and drag & drop value to timeline again.  
Love this timeline, very powerful. Thank Elastic SIEM team!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2019, 2:32am UTC](https://discuss.elastic.co/t/how-to-change-query-in-siem/204113/4 "2019-11-18T02:32:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
