# installing SIEM in ELK

**URL:** https://discuss.elastic.co/t/installing-siem-in-elk/350008
**Category:** Elastic Security
**Created:** [December 27, 2023, 7:20am UTC](https://discuss.elastic.co/t/installing-siem-in-elk/350008 "2023-12-27T07:20:24Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Maksim\_Alchinov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maksim_alchinov/32/122338_2.png) [@Maksim\_Alchinov](https://discuss.elastic.co/u/Maksim_Alchinov)
#### Post date: [December 27, 2023, 7:20am UTC](https://discuss.elastic.co/t/installing-siem-in-elk/350008/1 "2023-12-27T07:20:24Z")

</div>

Hello, I have installed the EKL stack on my test stand, for further work and analysis of logs we need to install SIEM. How can this be done? How can I load correlation rules for log analysis?

---

<div class="post-metadata">

### Author: ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)
#### Post date: [January 13, 2024, 9:55am UTC](https://discuss.elastic.co/t/installing-siem-in-elk/350008/2 "2024-01-13T09:55:14Z")

</div>

> [@Maksim\_Alchinov](#):
>
> Hello, I have installed the EKL stack on my test stand, for further work and analysis of logs we need to install SIEM. How can this be done? How can I load correlation rules for log analysis?

Hi,

Elastic Security, which includes the SIEM feature, is part of the basic license and is included by default in the Elastic Stack (formerly ELK Stack). You don't need to install it separately.

To access Elastic Security, you just need to open Kibana and click on "Security" in the left-hand navigation menu.

Regards

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 10, 2024, 9:55am UTC](https://discuss.elastic.co/t/installing-siem-in-elk/350008/3 "2024-02-10T09:55:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
