# Specific steps to build monitoring and siem with elk

**URL:** <https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605>\
**Category:** SIEM\
**Created:** [March 28, 2021, 8:38pm UTC](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605 "2021-03-28T20:38:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Depressed](https://avatars.discourse-cdn.com/v4/letter/d/8797f3/32.png) [@Depressed](https://discuss.elastic.co/u/Depressed)\
**Post date:** [March 28, 2021, 8:38pm UTC](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605/1 "2021-03-28T20:38:06Z")

</div>

Hi  
I'm kinda new to whole siem and elk things and before i managed to setup monitoring with splunk  
cracked enterprise edition and there all was simple as forwarding data from netflow ,syslog ,snmp  
and defining new field then manipulate date with some functions and making dashboard  
BUT  
it's been a week that I'm consulting elk and wazuh to receive syslog and netflow from pfsense to initiate setup and what i found some nonsense articles that point me to make filter and rules ....(idk)  
what i wanna do is to forward pfsense log and netflow ,cisco devices log and snmp ,windows server and client and linux servers suricata logs to elk (and wazuh )to make custom and predefined dashboards for monitoring  
would you plz explain me step to take for setup?  
TNX 🙂

---

<div class="post-metadata">

**Author:** ![Depressed](https://avatars.discourse-cdn.com/v4/letter/d/8797f3/32.png) [@Depressed](https://discuss.elastic.co/u/Depressed)\
**Post date:** [March 29, 2021, 3:18pm UTC](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605/2 "2021-03-29T15:18:42Z")

</div>

or at least point me somewhere to learn more...

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 29, 2021, 6:29pm UTC](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605/3 "2021-03-29T18:29:34Z")

</div>

I'd look at some of the free trainings we have:

> **[Free on-demand Elasticsearch and Kibana training](https://www.elastic.co/training/free)**
>
> Elastic offers free introductory training for the Elastic (ELK) Stack - Elasticsearch, Kibana, Beats and Logstash. Learn the fundamentals of observability (logging, metrics, APM), security, SIEM, ML, & more with on-demand training.

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [March 29, 2021, 9:09pm UTC](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605/4 "2021-03-29T21:09:09Z")

</div>

> [@Depressed](#):
>
> Hi  
> I'm kinda new to whole siem and elk things and before i managed to setup monitoring with splunk  
> cracked enterprise edition and there all was simple as forwarding data from netflow ,syslog ,snmp  
> and defining new field then manipulate date with some functions and making dashboard  
> BUT  
> it's been a week that I'm consulting elk and wazuh to receive syslog and netflow from pfsense to initiate setup and what i found some nonsense articles that point me to make filter and rules ....(idk)  
> what i wanna do is to forward pfsense log and netflow ,cisco devices log and snmp ,windows server and client and linux servers suricata logs to elk (and wazuh )to make custom and predefined dashboards for monitoring  
> would you plz explain me step to take for setup?  
> TNX 🙂

Are you using Wazuh? Because Wazuh uses "Open Distro for Elasticsearch" so you should look for that community.

**WAZUH**

- [Redirecting to Google Groups](https://groups.google.com/forum/#!forum/wazuh)
- [Join us on Slack | Wazuh](https://wazuh.com/community/join-us-on-slack/)

**Open Distro for Elasticsearch**

- [https://discuss.opendistrocommunity.dev](https://discuss.opendistrocommunity.dev)

I have made some blogs posts that could help you 😆 - [https://songer.pro](https://songer.pro)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2021, 9:09pm UTC](https://discuss.elastic.co/t/specific-steps-to-build-monitoring-and-siem-with-elk/268605/5 "2021-04-26T21:09:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
