# SIEM alert based on CVE

**URL:** <https://discuss.elastic.co/t/siem-alert-based-on-cve/311251>\
**Category:** Elastic Security\
**Created:** [August 3, 2022, 3:04am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251 "2022-08-03T03:04:32Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [August 3, 2022, 3:04am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/1 "2022-08-03T03:04:32Z")

</div>

I'm currently ingesting vulnerability data into elastic, including CVE ID. I would like to generate an alert whenever a vulnerabilty is ingested that shows up on a predefined list of "priority" CVEs. I'm not quite sure the best way to approach this and was hoping to get some input to point me in the right direction.

In splunk I'd set my list of priority CVEs as a lookup list and query for matches in my lookup list, but I know Elastic doesn't work that way.

Is there a way to build an alert to trigger when a value shows up in two different indexes (my vulnerability in one index and my priority CVEs in another)?

I did look at potentially using an indicator match rule but reviewing the documentation I'm not entirely clear if I could ingest the list of CVEs and set it as a indicator index pattern.

Is there a different, or perhaps more appropriate solution I may be missing?

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [August 3, 2022, 4:44am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/2 "2022-08-03T04:44:51Z")

</div>

There is a `lookup` runtime field type in Elasticsearch [Retrieve a runtime field | Elasticsearch Guide [8.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-retrieving-fields.html#lookup-runtime-fields). This should give you something similar to Splunk.

And then you can create a rule to trigger an alert based on the runtime field.

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [August 4, 2022, 4:10am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/3 "2022-08-04T04:10:46Z")

</div>

Hey Hendry, thanks for sharing the runtime lookup - I didn't know that existed. I've been testing the sample query provided in the documentation. I can query just fine but when attempting to create a rule it errors out that runtime\_mappings isn't a valid field. Not sure if I'm misunderstanding something or if this isn't support:

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a31598875001adcdef53c0d974f920fd41702ce.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [August 4, 2022, 12:34pm UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/4 "2022-08-04T12:34:31Z")

</div>

Which Elasticsearch version are you using?

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [August 4, 2022, 3:01pm UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/5 "2022-08-04T15:01:40Z")

</div>

8.3.1 in Elastic Cloud.

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [August 4, 2022, 11:49pm UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/6 "2022-08-04T23:49:41Z")

</div>

How did you try to use `runtime_mappings`? `runtime_mappings` can only be used in query DSL.  
If it's not supported, you can always add a runtime field to your index directly or Kibana data view.

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [August 5, 2022, 2:10am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/7 "2022-08-05T02:10:21Z")

</div>

I tried to use runtime\_mappings in an elasticsearch query rule. I copied the runtime query from the link you shared into the elasticsearch query rule. You had mentioned I could create a rule to trigger an alert based on the runtime field - are you saying that I'm missing a step or are you saying that it's not supported?

Appreciate the help - this seems much more difficult to accomplish in Elastic than I anticipated.

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [August 5, 2022, 2:23am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/8 "2022-08-05T02:23:57Z")

</div>

There are 3 ways to define runtime fields in Elasticsearch.

1. Query DSL
2. Runtime field mapping in the index
3. Kibana data view

If the Elastic Security query rule does not support runtime field, you will have to use one of the other 2 options.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2022, 2:24am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251/9 "2022-09-02T02:24:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
