# How to modify overview tap in elastic security app

**URL:** <https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193>\
**Category:** Elastic Security\
**Created:** [November 4, 2020, 1:01am UTC](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193 "2020-11-04T01:01:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![111387](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111387/32/75408_2.png) [@111387](https://discuss.elastic.co/u/111387)\
**Post date:** [November 4, 2020, 1:01am UTC](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193/1 "2020-11-04T01:01:38Z")

</div>

I set some IPS logs into ECS format using Fluentd and then delivered them to elasticsearch.

And you can see that the log is coming in from kibana.

The problem is that Elastic Security's Overview tap doesn't show the number of incoming events in Network events.

It is checked in the events at the top, but the number of events cannot be checked in the host events and network events below.

 ![스크린샷 2020-11-04 오전 9.36.28](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cca902a73eb7f558e662078b873da445d11631c8.png)

I'm not going to use beats. However, it seems that you can only check specific equipment events coming to beats.

How can I express the number of events of different equipment?

---

<div class="post-metadata">

**Author:** ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)\
**Post date:** [November 4, 2020, 3:53am UTC](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193/2 "2020-11-04T03:53:26Z")

</div>

Hi @111387!

By default, the Security solution uses the following Elasticsearch indices specified by the `securitySolution:defaultIndex` setting in Kibana Advanced settings:

```auto
apm-*-transaction*, auditbeat-*, endgame-*, filebeat-*, logs-*, packetbeat-*, winlogbeat-*

```

 ![kibana-advanced-settings](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca6618bd6bc1426402368412c4e8ab1b9f1af349.png)

You may add additional ECS-conforming indices to the setting shown in the screenshot above.

After adding the indices to the `securitySolution:defaultIndex` setting, they will be represented in the `Events` widget shown in the screenshot you provided, however they will not be shown in the `Network events` widget on the Overview, because that widget counts events from specific `agent.type`s, i.e. `agent.type: "auditbeat"`.

### We're always open: Inspect the queries that power the Security app

Tip: You may hover over widgets throughout the Security app and click `Inspect` to view the Elasticsearch query that powers the widget.

For example, hover over the `Network events` widget and click the `Inspect` button:

 ![inspect-network-events](https://us1.discourse-cdn.com/elastic/original/3X/7/9/799bfb6a94aeb543fa9cae13745a13d2e9b42db1.png)

the `Request` tab shown in the screenshot below will display the Elasticsearch query used to retrieve the counts shown in the `Network events` widget:

 ![request-tab](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9aab5cb0ae4a01e54e9b0706fee24d9a8e6367f7.jpeg)

Thanks for your question!

---

<div class="post-metadata">

**Author:** ![111387](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111387/32/75408_2.png) [@111387](https://discuss.elastic.co/u/111387)\
**Post date:** [November 6, 2020, 4:41am UTC](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193/3 "2020-11-06T04:41:09Z")

</div>

i know to bring results through Inspect Network events Ruquests.

But is it possible for me to edit the Inspect Network events Ruquests?

---

<div class="post-metadata">

**Author:** ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)\
**Post date:** [November 6, 2020, 6:14pm UTC](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193/4 "2020-11-06T18:14:37Z")

</div>

> [@111387](#):
>
> i know to bring results through Inspect Network events Ruquests.
> 
> But is it possible for me to edit the Inspect Network events Ruquests?

Thanks again for your question and feedback @111387! It's not possible to customize the query in the current implementation, so I created the following Github issue to track this feature as part of a refreshed design of the `Host events` and `Network events`:

> <https://github.com/elastic/kibana/issues/82872>
>
> The \`Host events\` and \`Network events\` widgets on the Security Solution \`Overvie…w\` page, shown in the screenshot below:
> 
> \- Were developed before the existence of \[Elastic Agent\](https://www.elastic.co/guide/en/ingest-management/master/fleet-overview.html) integrations. Thus, they are mostly organized around Beats, and don't display counts from Elastic Agent integrations
> 
> \- Don't count data ingested from custom data sources, \[as requested here\](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193)
> 
> \- Do not provide a means of hiding data sources that will always return a count of \`0\` when users know those sources are not providing data, because they are not in use
> 
> \<img width="762" alt="host-events-network-events" src="https://user-images.githubusercontent.com/4459398/98397472-a25b5600-201c-11eb-9c61-2ab022aaa31b.png"\>
> 
> 
> \### Considerations for a refreshed design
> 
> A refreshed design of these widgets should take into consideration:
> 
> \- Fleet's \[integrations for popular services and platforms\](https://www.elastic.co/guide/en/ingest-management/master/fleet-overview.html#fleet) ingested via Elastic Agent, as illustrated by the screenshot below
> 
> !\[integrations\](https://user-images.githubusercontent.com/4459398/98396468-fbc28580-201a-11eb-8f01-6664c2660395.png)
> 
> \- The ability to display counts of data ingested by custom data sources \[as requested here\](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193). The refreshed design should consider whether this can / should be achieved by convention, configuration, or a combination thereof.
> 
> \- An option for users to hide data sources that will always be reported with a count of \`0\`, because data from those sources will not be ingested, as requested by @stiltz
> 
> \*\*Kibana/Elasticsearch Stack version:\*\*
> 
> \`7.10\`

I linked the issue above to this post. Please feel free to comment directly in that issue or in this post with any additional details that might be relevant to your specific use case, as this may help inform the new design.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:16am UTC](https://discuss.elastic.co/t/how-to-modify-overview-tap-in-elastic-security-app/254193/5 "2022-11-04T08:16:54Z")

</div>


