# SIEM Hosts/All Hosts Tables Empty

**URL:** <https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832>\
**Category:** SIEM\
**Created:** [July 10, 2019, 4:48pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832 "2019-07-10T16:48:24Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 10, 2019, 4:48pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/1 "2019-07-10T16:48:24Z")

</div>

Started playing with SIEM after upgrading our Stack and some agents to 7.2. I currently have winlogbeat and auditbeat sending data to our stack. Auditbeat has the host and process modules enabled, winlogbeat is sending Application, Security, and System logs. The Overview page shows the following:

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/739a6de1c6870c521df41cc1d5f7577fdf2fbe37.png)

However, going into the Hosts section, most of the tables are empty.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d9a8bc41bc276d449e2e19b80783ff59e8d70cc.png)

What agent/configurations are needed to pull this information or are these tables only filled by non-Windows systems?

---

<div class="post-metadata">

**Author:** ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)\
**Post date:** [July 11, 2019, 4:38am UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/2 "2019-07-11T04:38:15Z")

</div>

Hi Walker, thanks for trying the Elastic SIEM beta!

Beats running 7.2 or later write events that conform to the [Elastic Common Schema](https://www.elastic.co/blog/introducing-the-elastic-common-schema).

The default index patterns for SIEM events are `auditbeat-*` , `winlogbeat-*` , `filebeat-*` , and `packetbeat-*`.

If the indices named above are only populated with data from older versions of Beats that don't yet conform to the [Elastic Common Schema](https://www.elastic.co/blog/introducing-the-elastic-common-schema), the widgets in the SIEM app won't show much, if any data.

The [SIEM Guide (Beta) 7.2 » Get up and running](https://www.elastic.co/guide/en/siem/guide/current/install-siem.html) guide includes links to the latest versions of Beats that populate events that conform to the [Elastic Common Schema](https://www.elastic.co/blog/introducing-the-elastic-common-schema).

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 11, 2019, 4:17pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/3 "2019-07-11T16:17:08Z")

</div>

I must be doing something wrong with my Elastic Stack in general, everytime I update, then manually setup the template for beats agents, I have to delete previous indices to resolve mapping conflicts.

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [July 15, 2019, 10:08am UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/4 "2019-07-15T10:08:27Z")

</div>

In general, for the `All Hosts` table to work, you need documents containing a `host.name` field. Can you check you do, and maybe post an example JSON document from the Auditbeat Process dataset?

---

<div class="post-metadata">

**Author:** ![Gael\_RICHIER](https://avatars.discourse-cdn.com/v4/letter/g/85f322/32.png) [@Gael\_RICHIER](https://discuss.elastic.co/u/Gael_RICHIER)\
**Post date:** [July 16, 2019, 3:55pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/5 "2019-07-16T15:55:48Z")

</div>

Hi, I'm in same case.  
I have Filebeat with system module and Auditbeat with all default module (except process and socket) and my hosts table in SIEM is empty (also Authentication).

In auditbeat error log I have this error : "error encoding host information: gob: type host.Host has no exported fields "

In JSON document host.name is defined.

Autidbeat and Filebeat send document to logstash

Elasticsearch 7.2  
Filebeat 7.2  
Auditbeat 7.2  
Logstash 7.2

 ![S%C3%A9lection_066](https://us1.discourse-cdn.com/elastic/original/3X/4/4/449854fa66ee7eb6575230769230dc49d4f19ed2.png)  
 ![S%C3%A9lection_065](https://us1.discourse-cdn.com/elastic/original/3X/9/4/94870bc87a5ba58fe62f9ce2865d265485b02849.png)

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 16, 2019, 8:47pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/6 "2019-07-16T20:47:14Z")

</div>

To resolve my issue, I had to delete all winlogbeat indices and manually reload the index template from a winlogbeat agent.

There's probably a better way to do it without loosing data, but that's how I did it. The same with stuff that populates from auditbeat (such as the OS name in the host info).

---

<div class="post-metadata">

**Author:** ![Gael\_RICHIER](https://avatars.discourse-cdn.com/v4/letter/g/85f322/32.png) [@Gael\_RICHIER](https://discuss.elastic.co/u/Gael_RICHIER)\
**Post date:** [July 17, 2019, 7:54am UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/7 "2019-07-17T07:54:56Z")

</div>

I resolve a part of my issue too, I had 2 filebeat-\* pattern in my kibana index and one of them needed to "refresh field list". I had to delete both and recreated a new one.

But I still have an error with auditbeat module host "error encoding host information: gob: type host.Host has no exported fields ". No IP address, no mac address and no Authentications.

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [July 17, 2019, 10:51am UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/8 "2019-07-17T10:51:50Z")

</div>

Hi @Gael_RICHIER, the error from the host dataset is a bug, I've just [submitted a fix](https://github.com/elastic/beats/pull/12940).

> [@Gael\_RICHIER](#):
>
> No IP address, no mac address and no Authentications.

The error message means it cannot write the host information to disk to persist between restarts, but it should still send host events containing IPs and MACs to Elasticsearch. Can you confirm that you have no documents with `event.dataset: host` in your data?

On authentications, this is collected by the Login dataset, and from your screenshot of the `Host Events` widget it looks like you have login events?

---

<div class="post-metadata">

**Author:** ![Gael\_RICHIER](https://avatars.discourse-cdn.com/v4/letter/g/85f322/32.png) [@Gael\_RICHIER](https://discuss.elastic.co/u/Gael_RICHIER)\
**Post date:** [July 17, 2019, 2:23pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/9 "2019-07-17T14:23:10Z")

</div>

Hi @cwurm, finally I deleted auditbeat elastic index and kibana index pattern and I re-setup autidbeat ('auditbeat setup') . After that, SIEM Authentication, IPs and MACs work ! 🙂 .

Thanks for your help.

PS: I encountered an other issue with auditbeat 7.2 on an Ubuntu 14.04 , kernel 3.13, but I think that it's not in the same subject. After started auditbeat, I have an infinite loop error on log file ('select() error: Operation not permitted').

---

<div class="post-metadata">

**Author:** ![westywill](https://avatars.discourse-cdn.com/v4/letter/w/7bcc69/32.png) [@westywill](https://discuss.elastic.co/u/westywill)\
**Post date:** [August 2, 2019, 4:25pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/10 "2019-08-02T16:25:33Z")

</div>

We also had this happen after indices were set to read-only due to low disk. I expanded the disk, set ES to write again. I deleted all indices and index patterns. Still no hosts in SIEM aside from local Filebeat. Running all 7.2

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [August 2, 2019, 6:40pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/11 "2019-08-02T18:40:44Z")

</div>

I believe the host data is pulled via the auditbeat agent.

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [August 5, 2019, 1:03pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/12 "2019-08-05T13:03:12Z")

</div>

All Beats should be reporting a `host.name` since 7.0 if using the default configuration (via the `add_host_metadata` processor). If that field is filled, it should show up in the All Hosts table.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2019, 1:03pm UTC](https://discuss.elastic.co/t/siem-hosts-all-hosts-tables-empty/189832/13 "2019-09-02T13:03:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
