I have recently spent a lot of time getting a few of my data sources ingested in ECS format so that I can get the benefits from the SIEM capability. Some data comes direct from the *beats tools but some are via Logstash so I can do some conversion. This all seems to be working with no errors in the various tools - I have had many tweaks to make as Signals needed the data in a very specific format so as that is all working, I believe my data is in a good place.
Since adding more data, I have started to get errors on the Network page in the SIEM tool which are quite hard to debug so I have 2 questions.
Is there any way to get access to the SIEM dashboards? The network dashboard looks to have a number of visualisations but I can't find them to check what they are querying or to edit. This would help identify which visualisaiton(s) are causing the errors.
One of the visualisations is reporting that it is querying all indexes - even those that the SIEM is not supposed to query. I have added 1 custom index under Management > Advanced Settings > SIEM > Elasticsearch indices so it now reads:
apm-*-transaction*, auditbeat-*, endgame-*, filebeat-*, packetbeat-*, winlogbeat-*, ecs-*
The problem is that I am seeing queries to other indexes which I don't want queried on this dashboard or by SIEM at all. The images shown below show a query to a logstash-* index failure as there is no geo_point - this is not ECS formatted data yet so I don't expect it to work with SIEM. The second image shows a query to the .siem index - I don't know which visualisation would need to query that so also seems out of place?
The shot below shows the data from Inspecting the Map on the Network page. This suggests there are queries to * which I am guessing may be where the problem lies as its querying all indexes? Again, without the ability to view the settings of the map visual, I don't know.
Does this seem like correct behaviour?