# SIEM and XDR Alerts

**URL:** <https://discuss.elastic.co/t/siem-and-xdr-alerts/359963>\
**Category:** Elastic Security\
**Created:** [May 22, 2024, 7:37am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963 "2024-05-22T07:37:16Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [May 22, 2024, 7:37am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/1 "2024-05-22T07:37:16Z")

</div>

Hi,

is possible to differentiate alert detections between SIEM and XDR on the console?

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [May 24, 2024, 2:00pm UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/2 "2024-05-24T14:00:04Z")

</div>

In _Security \> Rules \> Detection Rules_ you will find all the rules related to the integration of Elastic Defend which takes EDR actions and, when used for protection in cloud or container services, assumes the role of XDR delivering scalable and extended protection for these services.

 ![rules01](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0a20ad1e036693362363d76cd26e368e0913ec80.png)

 ![Rules02](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c9d245cedb846abf487e212f0963d6ae25b91c3d.png)

 ![Rule03](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0ff0323b747f7fdf74e4db1379bf504a7a758f17.png)

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [May 30, 2024, 5:50am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/3 "2024-05-30T05:50:54Z")

</div>

@wsouza Thanks for the feedback . but this is based on the rule right? is it possible to pull alerts for a month for example the one only XDR detected?

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [June 4, 2024, 12:28am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/4 "2024-06-04T00:28:15Z")

</div>

When creating a detection rule, you can add an exception to the endpoint. You find this option in Advanced Settings when creating a detection rule. Does it help you with anything?

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/9/098280b444383fda8485277b96ac373be9549c19.png)

> **[Create a detection rule | Elastic Security Solution \[8.13\] | Elastic](https://www.elastic.co/guide/en/security/current/rules-ui-create.html)**

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [June 7, 2024, 5:33am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/5 "2024-06-07T05:33:23Z")

</div>

Hi @wsouza Thanks i thought maybe i can separate xdr alerts and siem alerts not on the rules but on the alerts.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 7, 2024, 10:33am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/6 "2024-06-07T10:33:37Z")

</div>

I think it's possible with the right query / filter on the right tags.

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [June 7, 2024, 2:25pm UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/7 "2024-06-07T14:25:13Z")

</div>

Hi @willemdh oh okay any idea?

---

<div class="post-metadata">

**Author:** ![guessWho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guesswho/32/135240_2.png) [@guessWho](https://discuss.elastic.co/u/guessWho)\
**Post date:** [June 8, 2024, 9:37pm UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/8 "2024-06-08T21:37:55Z")

</div>

If you are looking at _Security \> Alerts_, you can filter with `event.dataset:"endpoint.alerts"`. This will show you all the alerts coming from the _Endpoint Security_ rule.

If you want to have a broader scope to include all detection alerts that use the logs coming from the Defend integration, you can filter on the alert page with `event.dataset:endpoint.*`. This would include datasets like `endpoint.events.file`, `endpoint.events.network`, `endpoint.events.process`, etc.

Hopefullly this helps!

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [June 11, 2024, 5:12am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/9 "2024-06-11T05:12:23Z")

</div>

Hi @guessWho Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2024, 5:13am UTC](https://discuss.elastic.co/t/siem-and-xdr-alerts/359963/10 "2024-07-09T05:13:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
