# "SMTP to Internet" signal detection rule is not fired up by Elastic SIEM

**URL:** <https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754>\
**Category:** SIEM\
**Created:** [June 11, 2020, 4:52pm UTC](https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754 "2020-06-11T16:52:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jelocabral](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jelocabral](https://discuss.elastic.co/u/jelocabral)\
**Post date:** [June 11, 2020, 4:52pm UTC](https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754/1 "2020-06-11T16:52:18Z")

</div>

Hi people, I'm new at this forum so nice to meet you.

I'm testing the detection power of Elastic SIEM and in some cases it doesn't detect the rule events. This is a case:

Signal detection rule: SMTP to Internet (it's a pre-built rule)  
Index patterns: filebeat-\*  
Custom query: network.transport:tcp and destination.port:(25 or 465 or 587) and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip:(10.0.0.0/8 or 127.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16 or "::1")

In one of my server with filebeat, I execute "telnet x.x.x.x 25" (x.x.x.x is the public IP from a SMTP server), but when I go to Discover and select the Filebeat index to look for the query fields, I see that the following fields don't exist in the given index:

source.ip  
destination.ip  
destination.port

Is it possible that these fields don't appear in filebeat index because of my filebeat configuration ?

filebeat.inputs:

- type: log  
enabled: true  
paths:

Because the "SMTP to Internet" pre-built rule searches into filebeat-\* by default.

Thank yoy very much.

Jelo

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [June 12, 2020, 9:19pm UTC](https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754/2 "2020-06-12T21:19:50Z")

</div>

Hey there Jelo -- thanks for joining the community! 🙂

And yes, you are correct about those fields not being populated because of your configuration. For `filebeat` to index those fields you'll either need to add a module that populates those fields ([Cisco](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-cisco.html), [haproxy](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-haproxy.html), [Netflow](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-netflow.html), [Suricata](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-suricata.html), [Zeek](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-zeek.html)), or have a log file that has those fields present.

Alternatively, you could use `Packetbeat` or `Auditbeat` which would cover most of the other Network rules as well.

Hope that helps, and let us know if you have any issues getting the rule to fire once those fields are populated. Cheers!

Garrett

---

<div class="post-metadata">

**Author:** ![jelocabral](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jelocabral](https://discuss.elastic.co/u/jelocabral)\
**Post date:** [June 16, 2020, 1:35pm UTC](https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754/3 "2020-06-16T13:35:04Z")

</div>

Hi Garret, I've just read your response.

Thanks a lot for your useful help.

Cheers !!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2020, 1:35pm UTC](https://discuss.elastic.co/t/smtp-to-internet-signal-detection-rule-is-not-fired-up-by-elastic-siem/236754/4 "2020-07-14T13:35:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
