# The suricata results shown on the \[filebeat dashboard\] are different from the results shown in the \[security -\> alerts\] on kibana

**URL:** <https://discuss.elastic.co/t/the-suricata-results-shown-on-the-filebeat-dashboard-are-different-from-the-results-shown-in-the-security-alerts-on-kibana/366226>\
**Category:** SIEM\
**Created:** [September 9, 2024, 7:33am UTC](https://discuss.elastic.co/t/the-suricata-results-shown-on-the-filebeat-dashboard-are-different-from-the-results-shown-in-the-security-alerts-on-kibana/366226 "2024-09-09T07:33:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lilyyy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lilyyy/32/51129_2.png) [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Post date:** [September 9, 2024, 7:33am UTC](https://discuss.elastic.co/t/the-suricata-results-shown-on-the-filebeat-dashboard-are-different-from-the-results-shown-in-the-security-alerts-on-kibana/366226/1 "2024-09-09T07:33:37Z")

</div>

I am using suricata module for the IDS and I am also activating suricata Integrations on SIEM.

The filebeat suricata dashboard was created in kibana, and the suricata alert dashboard can also be checked in kibana(Security -\> alerts).

Both come from the same data source, but when comparing the data, the results are different.

[filebeat suricata data]

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/4/44126f9d7f188c1d8ad7326fdd661740676ec630.png)

[SIEM: Security -\> alerts]

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d440db7190f5896375aae1195d5301b2dd07b4d3.png)

Both are filtered by 'Potentially bad traffic' and same date but [filebeat suricata] results are 27 and SIEM results are 25.

Is there anyone who knows why the results are different even though data source is same?

Thank you.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 1, 2024, 2:40pm UTC](https://discuss.elastic.co/t/the-suricata-results-shown-on-the-filebeat-dashboard-are-different-from-the-results-shown-in-the-security-alerts-on-kibana/366226/2 "2024-10-01T14:40:51Z")

</div>

These two views are looking at different data sources.

- The first is looking at the raw events from Suricata.

- The second is looking at alerts in `.alerts-security.alerts-default`. These would events would have been put here by a detection rule. There is generic rule called [External Alerts](https://www.elastic.co/guide/en/security/current/external-alerts.html) that takes alert events from external systems like suricata and "promotes" them to be Elastic SIEM alerts.

So the difference might just be related to timing. I think the `@timestamp` on the data in the .alerts index is when the rule triggered. The time from the original suricata alert should also be in there, but under a different field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2024, 2:41pm UTC](https://discuss.elastic.co/t/the-suricata-results-shown-on-the-filebeat-dashboard-are-different-from-the-results-shown-in-the-security-alerts-on-kibana/366226/3 "2024-10-29T14:41:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
