# SIEM with Basic License On-Prem?

**URL:** https://discuss.elastic.co/t/siem-with-basic-license-on-prem/272109
**Category:** SIEM
**Created:** [May 4, 2021, 6:59pm UTC](https://discuss.elastic.co/t/siem-with-basic-license-on-prem/272109 "2021-05-04T18:59:51Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![R99Stny](https://avatars.discourse-cdn.com/v4/letter/r/e9a140/32.png) [@R99Stny](https://discuss.elastic.co/u/R99Stny)
#### Post date: [May 4, 2021, 6:59pm UTC](https://discuss.elastic.co/t/siem-with-basic-license-on-prem/272109/1 "2021-05-04T18:59:51Z")

</div>

We have a 3 node cluster on prem 7.6. Couple questions:

1. Based on the docs we should be able to see and use pre-built detections with only a basic license?
2. We do need (required to) have tls/ssl set up within the cluster, an encryption key created before we can access / see the detection rules? Is there anything else needed?

any insight that can be shared regarding set up of security in an on-prem situation that enables the default Security functions would be appreciated.

Thanks

---

<div class="post-metadata">

### Author: ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)
#### Post date: [May 5, 2021, 12:56am UTC](https://discuss.elastic.co/t/siem-with-basic-license-on-prem/272109/2 "2021-05-05T00:56:27Z")

</div>

Welcome to the community @R99Stny!

> [@R99Stny](#):
>
> We have a 3 node cluster on prem 7.6. Couple questions:

The Elastic Security solution has come a looooong way since the `7.6` release. If you're just getting started with it and want to explore the detection rules before putting them into production, you may consider [spinning up a free trial instance on Elastic cloud](https://www.elastic.co/cloud/) as an alternative fast-path to experiencing what the latest version has to offer.

> [@R99Stny](#):
>
> Based on the docs we should be able to see and use pre-built detections with only a basic license?

Yes, the pre-built detections are free to use with the Basic license. You may also create your own custom detection rules for free with the Basic license.

> [@R99Stny](#):
>
> We do need (required to) have tls/ssl set up within the cluster, an encryption key created before we can access / see the detection rules? Is there anything else needed?

The [Detections prerequisites and requirements](https://www.elastic.co/guide/en/security/current/detections-permissions-section.html) guide has the latest documentation for configuring detection rules on a self-managed Elastic Stack.

There doesn't appear to be a `7.6` version of the above guide, so your milage may (greatly) vary if the details in that guide are applied to a `7.6` deployment.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 2, 2021, 12:56am UTC](https://discuss.elastic.co/t/siem-with-basic-license-on-prem/272109/3 "2021-06-02T00:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
