# Kibana SIEM "External Alert"

**URL:** <https://discuss.elastic.co/t/kibana-siem-external-alert/220643>\
**Category:** SIEM\
**Created:** [February 24, 2020, 12:12pm UTC](https://discuss.elastic.co/t/kibana-siem-external-alert/220643 "2020-02-24T12:12:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [February 24, 2020, 12:12pm UTC](https://discuss.elastic.co/t/kibana-siem-external-alert/220643/1 "2020-02-24T12:12:16Z")

</div>

Hello,

I was wondering how we can use the 'External Alert' functionality in Kibana SIEM 7.6.0? The documentation is rather sparse ([https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#\_signals\_and\_external\_alerts](https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#_signals_and_external_alerts))

How do we make it pick up external alerts? What conditions need to be met for data to be visualised in 'External Alerts'?

Willem

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [February 24, 2020, 3:18pm UTC](https://discuss.elastic.co/t/kibana-siem-external-alert/220643/2 "2020-02-24T15:18:53Z")

</div>

Hi willemdh,  
You just have to set ECS categorization field `event.kind:"alert"`. To get full use of the "Stack by" functions on the overview and detections pages, also populate `event.module` and `event.category`. To get hyperlinks back to the source of alert, you can populate `rule.reference` with a URL.

Hope this helps,  
Mike P.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [February 24, 2020, 6:40pm UTC](https://discuss.elastic.co/t/kibana-siem-external-alert/220643/3 "2020-02-24T18:40:58Z")

</div>

Mike,  
Actually the way you are describing how it works, is exactly how I was hoping it would work. I already started flagging event.Kind with Alert's some time ago, so this should play out perfect.  
We will wait for 7.6.1 however before upgrading our PR cluster, but I will play with this functionality in our QA.  
TX!  
Willem

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [March 19, 2020, 11:11am UTC](https://discuss.elastic.co/t/kibana-siem-external-alert/220643/4 "2020-03-19T11:11:43Z")

</div>

Hello,

Just wanted to confirm I got this working. But I noticed that there seems to be no way to define which columns are shown currently?

The default column list is very unlogical..

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/9/99b01b8283db59899fd5998684a2c8d8dcafc0f0.png)

First of all observer.name isn't even an ecs field. Also I need to observer.hostname to be the first column. I can configure this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/0/60046e4bada91b430447a983b9cb27546efffa96.png)

But when reloading the page, everything is reverted to the default column setup? Or am I missing something?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2020, 11:12am UTC](https://discuss.elastic.co/t/kibana-siem-external-alert/220643/5 "2020-04-16T11:12:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
