SIEM detection engine is not getting started

Hi @ankitdevnalkar,

  • HTTP S is configured : no have not configured it. I am running on http. As I couldn't find it in any documentation that HTTPS is necessary.

Yeah, HTTPS communication between Elasticsearch and Kibana is required in order for ensure the secure operation of the detection engine.

I'm wondering if the documentation is confusing with its use of "on-premises"? You mention that you're running your Stack in AWS, but since you are managing your own stack, it needs to meet these prerequisites and requirements.

This blog contains a nice 7-minute video that describes how to enable HTTPS between Elasticsearch and Kibana. Note: The video was created on an older version of the the Stack, but I found it helpful to understand what needs to be done.

1 Like