Hi Guys,
the new elastic SIEM timeline feature looks amazing and I would like to use it for log analysis.
Unfortunately I don't have that much experience regarding ELK setup.
If i understand correctly it is only possible to use the SIEM functionality in combination with an input like Filebeat or Packet Beat.
In our use case we don't want to have a kind of "live" input. We want to add manually data (e.g. windows or linux log files) into the ELK-stack and analyze the data using the SIEM timeline functionality. Is that possible at the moment? I only found the possibility to import data directly by Filebeat or other stuff.
The overall aim would be to use the Elastic SIEM as a replacement for Timesketch (https://github.com/google/timesketch).
Thank you in advance and best greetings
Intelli