# SIEM feature request

**URL:** <https://discuss.elastic.co/t/siem-feature-request/250340>\
**Category:** SIEM\
**Created:** [September 29, 2020, 10:40am UTC](https://discuss.elastic.co/t/siem-feature-request/250340 "2020-09-29T10:40:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [September 29, 2020, 10:40am UTC](https://discuss.elastic.co/t/siem-feature-request/250340/1 "2020-09-29T10:40:51Z")

</div>

Hi,  
As i was scrolling down the huge pile of log and then i come up with this ideal for SIEM that i really want

What i want is the ability to detect multiple event subsequently, what i mean is that for example i have a huge pile of log from some ip that trying to bruteforce an account, then after that an event show that that ip successfully logon to that account which mean that account has been compromised, so i want to have a rule to detect multiple failed event and then for some period of time if the success event appear then the signal will be raised.

---

<div class="post-metadata">

**Author:** ![hmnichols](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hmnichols/32/76342_2.png) [@hmnichols](https://discuss.elastic.co/u/hmnichols)\
**Post date:** [September 29, 2020, 2:58pm UTC](https://discuss.elastic.co/t/siem-feature-request/250340/2 "2020-09-29T14:58:45Z")

</div>

Hi, thanks for reaching out. There is an existing feature that will get you partly there called threshold alerts. This capability of the detection engine would allow you to look for N number of events before triggering an alert. Here is the link to the docs on the feature: [https://www.elastic.co/guide/en/security/current/rules-ui-create.html](https://www.elastic.co/guide/en/security/current/rules-ui-create.html)

We also have some prebuilt threshold rules you can use as examples to build from: [https://www.elastic.co/guide/en/security/current/aws-iam-brute-force-of-assume-role-policy.html](https://www.elastic.co/guide/en/security/current/aws-iam-brute-force-of-assume-role-policy.html)

As for correlating numerous events (look for this and then that) we released an amazing new capability in Elasticsearch in 7.9 called Event Query Language (EQL). EQL is a new query language that allows for correlation of events in a simple and fast way. It is not yet leverage in the Security application, but stay tuned for more on that soon. [https://www.elastic.co/guide/en/elasticsearch/reference/master/eql.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/eql.html)

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [October 1, 2020, 2:48am UTC](https://discuss.elastic.co/t/siem-feature-request/250340/3 "2020-10-01T02:48:51Z")

</div>

Thanks for your replies @hmnichols  
What i really want is to able to query 2 field one after another rather than query them both at once, for example, event id log  
i want to query for event 4625 and then if event 4625 appear after like 5 minutes then the signal will be raised.

---

<div class="post-metadata">

**Author:** ![hmnichols](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hmnichols/32/76342_2.png) [@hmnichols](https://discuss.elastic.co/u/hmnichols)\
**Post date:** [October 1, 2020, 3:18pm UTC](https://discuss.elastic.co/t/siem-feature-request/250340/4 "2020-10-01T15:18:49Z")

</div>

This is exactly the power that EQL provides. Here is a generic example:  
sequence by field\_foo with maxspan=30s  
[event\_category\_1 where condition\_1] by field\_baz  
[event\_category\_2 where condition\_2] by field\_bar

More specific examples can be seen here: [https://www.elastic.co/guide/en/elasticsearch/reference/master/eql-ex-threat-detection.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/eql-ex-threat-detection.html)

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [October 1, 2020, 11:22pm UTC](https://discuss.elastic.co/t/siem-feature-request/250340/5 "2020-10-01T23:22:36Z")

</div>

Indeed EQL should fit perfectly for your use case, however, in the mean time your could use a watcher with some "advanced" queries and some scripts, the situation that you described is very similar to this example:

> **[elastic/examples](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches/lateral_movement_in_user_comm)**
>
> Home for Elasticsearch examples available to everyone. It's a great way to get started. - elastic/examples

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2020, 11:22pm UTC](https://discuss.elastic.co/t/siem-feature-request/250340/6 "2020-10-29T23:22:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
