# SIEM (Kibana) not working with some errors

**URL:** <https://discuss.elastic.co/t/siem-kibana-not-working-with-some-errors/267657>\
**Category:** SIEM\
**Tags:** elastic-stack-security\
**Created:** [March 18, 2021, 12:40pm UTC](https://discuss.elastic.co/t/siem-kibana-not-working-with-some-errors/267657 "2021-03-18T12:40:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_E](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_e/32/47012_2.png) [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Post date:** [March 18, 2021, 12:40pm UTC](https://discuss.elastic.co/t/siem-kibana-not-working-with-some-errors/267657/1 "2021-03-18T12:40:33Z")

</div>

I have the full ELK cluster experience with Filebeat sending logst to Logstash and there I do all my processing. I very recently learned that in order to have nested fields you should write "[host][name]" rather than "host.name" as I was doing. I learned all that from this webinar: [Integrating custom logs with ECS for Elastic SIEM | Elastic Videos](https://www.elastic.co/es/webinars/integrating-custom-logs-with-ecs-for-elastic-siem). So I was very happy to learn that I could actually use the SIEM for my own logs, I changed the format for the logstash filters accordingly and now I see the SIEM is actually doing something. However it gives me the following errors:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/a/eaee0e9f428a62c455a05a21fe5834e82dda3eac.png)

I've been trying to find out what they meant and found nothing anywhere. My guess is that I'm missing something in my logstash filters regarding the parameterization, but I don't see what it is since I've followed the same ideas the guy from the webinar talks about.

Any help with this issue? I could provide further information regarding my pipeline in logstash if necessary.

---

<div class="post-metadata">

**Author:** ![Jose\_E](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_e/32/47012_2.png) [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Post date:** [April 5, 2021, 10:20am UTC](https://discuss.elastic.co/t/siem-kibana-not-working-with-some-errors/267657/2 "2021-04-05T10:20:43Z")

</div>

I kind of fixed this by making sure I was properly defining "host.name" and "source.ip" as nested fields; after that I began seeing the SIEM full of hosts and the basic data. I'm also seeing a lot of conflicts in the index patterns since "source.ip" is now an IP rather than String, which is good.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2021, 10:21am UTC](https://discuss.elastic.co/t/siem-kibana-not-working-with-some-errors/267657/3 "2021-05-03T10:21:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
