# Logstash to LogRhythm SIEM

**URL:** <https://discuss.elastic.co/t/logstash-to-logrhythm-siem/141666>\
**Category:** Logstash\
**Created:** [July 25, 2018, 9:50pm UTC](https://discuss.elastic.co/t/logstash-to-logrhythm-siem/141666 "2018-07-25T21:50:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![valbizures](https://avatars.discourse-cdn.com/v4/letter/v/838e76/32.png) [@valbizures](https://discuss.elastic.co/u/valbizures)\
**Post date:** [July 25, 2018, 9:50pm UTC](https://discuss.elastic.co/t/logstash-to-logrhythm-siem/141666/1 "2018-07-25T21:50:03Z")

</div>

Has anyone had any success setting up Logstash to output directly to a LogRhythm SIEM?

If so can you provide some information as to the types of outputs you used for:

HTTP(S) - I'm currently using packetbeat  
DNS - I'm currently using packetbeat  
Windows Events - I'm currently using winbeat

My output today is currently syslog, but when I look at the logs on the SIEM they're not complete.

On another note does anyone know of any consulting companies out there that do this type of custom work? SIEM architecture/deployments involving Logstash and a commercial SIEM?

Thanks in advance .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2018, 9:50pm UTC](https://discuss.elastic.co/t/logstash-to-logrhythm-siem/141666/2 "2018-08-22T21:50:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
