SIEM Events/All Events Tables Empty

Finished setting up all the ELK and all looks fine until heading to SIEM page. For some reason the events table in SIEM is looking for fields that does not exist.

Can someone point me to the right direction to fix that?

Hi @francescouk, great that you got your ELK stack up and running!

The SIEM app, including all its pages (e.g., Hosts, Network, Detections, etc.) expects data to be normalized to the Elastic Common Schema (ECS). One common reason for data not appearing in SIEM tables is when data is not in ECS format.

ECS is an open source specification, developed with support from the Elastic user community. ECS defines a common set of fields to be used when storing event data in Elasticsearch. The goal of ECS is to enable and encourage users of Elasticsearch to normalize their event data, so that they can better analyze, visualize, and correlate the data represented in their events.

Please let us know if this helps.