# Publish data to Elastic SIEM

**URL:** <https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685>\
**Category:** SIEM\
**Created:** [July 8, 2024, 9:30am UTC](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685 "2024-07-08T09:30:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sateeshkumarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sateeshkumarb/32/135877_2.png) [@sateeshkumarb](https://discuss.elastic.co/u/sateeshkumarb)\
**Post date:** [July 8, 2024, 9:30am UTC](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685/1 "2024-07-08T09:30:36Z")

</div>

Hi,

I am trying to ingest some custom security event data (for which there is no Elastic integration) into Elastic SIEM. Looking at this chart:

> **[Elastic Cloud Data Ingestion - Start Here](https://www.elastic.co/customer-success/data-ingestion)**
>
> Here's a collection of resources to streamline your data ingestion into Elastic Cloud. Select your preferred learning methods--from video to documentation. Learn more about getting your data in, best ...

it seems only way to do so is via Elastic agent.

However I can't install Elastic Agent and I am looking for a ways to publish the event to Elastic SIEM using the REST APIs provided by Elastic (say something like `curl -X POST <elastic_url>/_bulk?pretty` ). Is this possible ?  
Or are there any alternative recommended ways to post security events to Elastic SIEM.

Any inputs are appreciated.

Thanks in advance,  
sateesh

---

<div class="post-metadata">

**Author:** ![sateeshkumarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sateeshkumarb/32/135877_2.png) [@sateeshkumarb](https://discuss.elastic.co/u/sateeshkumarb)\
**Post date:** [July 8, 2024, 9:38am UTC](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685/2 "2024-07-08T09:38:35Z")

</div>

From #Endpoint Security to #SIEM

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [July 8, 2024, 2:18pm UTC](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685/3 "2024-07-08T14:18:31Z")

</div>

Certainly it's possible to write documents directly to Elasticsearch. You'll need to create API key in the stack to attach it as http header with each request.

[Create API key API | Elasticsearch Guide [8.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html)

---

<div class="post-metadata">

**Author:** ![sateeshkumarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sateeshkumarb/32/135877_2.png) [@sateeshkumarb](https://discuss.elastic.co/u/sateeshkumarb)\
**Post date:** [July 8, 2024, 5:56pm UTC](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685/4 "2024-07-08T17:56:42Z")

</div>

@lesio Thanks for your input, I will try it out. Since the data ingestion page didn't list Elastic APl as one of the possible modes for ingestion, I was bit unsure.

Thanks,  
sateesh

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2024, 5:57pm UTC](https://discuss.elastic.co/t/publish-data-to-elastic-siem/362685/5 "2024-08-05T17:57:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
