# Inserting Logs into SIEM

**URL:** <https://discuss.elastic.co/t/inserting-logs-into-siem/188510>\
**Category:** SIEM\
**Created:** [July 2, 2019, 12:24pm UTC](https://discuss.elastic.co/t/inserting-logs-into-siem/188510 "2019-07-02T12:24:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![inteli](https://avatars.discourse-cdn.com/v4/letter/i/e9bcb4/32.png) [@inteli](https://discuss.elastic.co/u/inteli)\
**Post date:** [July 2, 2019, 12:24pm UTC](https://discuss.elastic.co/t/inserting-logs-into-siem/188510/1 "2019-07-02T12:24:03Z")

</div>

Hi Guys,

the new elastic SIEM timeline feature looks amazing and I would like to use it for log analysis.  
Unfortunately I don't have that much experience regarding ELK setup.

If i understand correctly it is only possible to use the SIEM functionality in combination with an input like Filebeat or Packet Beat.

In our use case we don't want to have a kind of "live" input. We want to add manually data (e.g. windows or linux log files) into the ELK-stack and analyze the data using the SIEM timeline functionality. Is that possible at the moment? I only found the possibility to import data directly by Filebeat or other stuff.

The overall aim would be to use the Elastic SIEM as a replacement for Timesketch ([https://github.com/google/timesketch](https://github.com/google/timesketch)).

Thank you in advance and best greetings  
Intelli

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [July 3, 2019, 10:12am UTC](https://discuss.elastic.co/t/inserting-logs-into-siem/188510/2 "2019-07-03T10:12:50Z")

</div>

Hi,

The SIEM app and the Timeline can work with data produced outside of the Beats ecosystem as long as it is using [ECS](https://github.com/elastic/ecs) for the field names. ECS is our one big requirement, without adopting ECS I'm afraid that you won't find the app very useful, at least in its current form.

Note that you can make the SIEM app look at other index patterns besides the Beats ones, see the "SIEM default index" setting in Kibana Advanced Settings.

Finally, there is an experimental CSV/JSON/log import in Kibana, you can find it in Kibana Home (click the Kibana logo). This might be a good way to experiment before setting up Filebeat to import your logs.

---

<div class="post-metadata">

**Author:** ![inteli](https://avatars.discourse-cdn.com/v4/letter/i/e9bcb4/32.png) [@inteli](https://discuss.elastic.co/u/inteli)\
**Post date:** [July 3, 2019, 11:17am UTC](https://discuss.elastic.co/t/inserting-logs-into-siem/188510/3 "2019-07-03T11:17:14Z")

</div>

Thank you!  
That helps a lot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2019, 11:17am UTC](https://discuss.elastic.co/t/inserting-logs-into-siem/188510/4 "2019-07-31T11:17:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
