# WHAT SIEM CAN DO?

**URL:** <https://discuss.elastic.co/t/what-siem-can-do/244483>\
**Category:** SIEM\
**Created:** [August 11, 2020, 3:53am UTC](https://discuss.elastic.co/t/what-siem-can-do/244483 "2020-08-11T03:53:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![syafeera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syafeera/32/47173_2.png) [@syafeera](https://discuss.elastic.co/u/syafeera)\
**Post date:** [August 11, 2020, 3:53am UTC](https://discuss.elastic.co/t/what-siem-can-do/244483/1 "2020-08-11T03:53:02Z")

</div>

Hi,

is there anyone here can explain to me a simple way what is SIEM? How can SIEM detect threat? what is IP destination and IP source means in SIEM? I really not clear about it.. Thanks

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [August 11, 2020, 7:18pm UTC](https://discuss.elastic.co/t/what-siem-can-do/244483/2 "2020-08-11T19:18:39Z")

</div>

SIEM and security is very broad and has many different context's depending on your individual and company goals as well as size and scope.

This is a good starter you can sign up for:  
[https://www.elastic.co/training/elastic-siem-fundamentals](https://www.elastic.co/training/elastic-siem-fundamentals)

We have lots of good blogs and series that go over a lot of different things as well:

> **[Elastic SIEM for small business and home: Getting started](https://www.elastic.co/blog/elastic-siem-for-small-business-and-home-1-getting-started)**
>
> Monitoring your servers and workstations does not have to be difficult or expensive. Elastic SIEM is a great way to provide security analytics and monitoring capabilities to small businesses and homes. Check out Part 1 of this new series to find out...

Elastic Security does have a detection engine which can detect events a.k.a "important things happening in your logs" and we have a lot of prepackaged rules/content that can do detection as well as pre-packaged machine learning jobs. Lots of good info here:

> **[Elastic SIEM detection engine with pre-built rules and analytics.](https://www.elastic.co/blog/elastic-siem-detections)**
>
> The Elastic SIEM detection Engine with pre-built rules and analytics provides SOC teams with a unified SIEM rule experience that draws from a purpose-built set of Elasticsearch analytics engines, and runs on a new distributed execution platform in...

And then our recently opened repo of content and rules here:

> **[Elastic Security opens public detection rules repo](https://www.elastic.co/blog/elastic-security-opens-public-detection-rules-repo)**
>
> Elastic Security has opened its detection rules repository to the world. We will develop rules in the open alongside the community, and we’re welcoming your community-driven detections. This is an opportunity to share collective security knowledge.

In a nutshell, SIEM or server side information event management is taking a bunch of log shippers/agents such as auditbeat, winlogbeat, endgame agents for endpoints, etc... and shipping these important log files and information to a central collection spot such as Elasticsearch in a structured manner in a common format called Elastic Common Schema (ECS).

Why this is important is if you imagine you have 10's or 100's of Linux servers, windows servers, routers, endpoint users, etc... where you want to search through the auditd logs, firewall logs, 3rd party product logs, vendor logs, etc... looking for intrusion attempts or intrusion successes or where someone is violating company policies such as using insecure versions of TLS ciphers how are you going to do it at scale? You don't want to go to each computer or remote log in each day into these computers. At this point you need a way to centrally collect them and be able to quickly search through them in near real time or historically and this what the log/agent/sensor shippers such as beats, endgame agents, etc... are used for. Detections is used for creating rules to where you can automate finding the things you are looking for and sending you an alert via email, slack instant messaging etc... in close to real time.

Beats and other security agents will use a normalized common schema for each of these. Lots of different log files from different vendor products will label things in their unstructured log files differently. It would be tricky if you have a type of firewall log file that wants to label a host name as "hostName" and then another elastic document from another firewall log file label it as "host.name" and then another just label it as "hName"

Then your KQL search for your host name of "foo" would be: `"hostName: "foo" or host.name: "foo" or hName: "foo"`, and you begin getting an "OR" explosion of different ways of searching. So the best way to move forward is to normalize as much of this as possible from these different log files into one _common_ format.

Good blog post on ECS:

> **[Elastic Common Schema (ECS): The Common Event Model for Elasticsearch](https://www.elastic.co/blog/introducing-the-elastic-common-schema)**
>
> Introducing the Elastic Common Schema (ECS), a new specification that provides a consistent and customizable way to structure your data in Elasticsearch, helping machine learning jobs be applied more broadly, searches be crafted more narrowly, and...

Also reference information here:  
[https://www.elastic.co/guide/en/ecs/current/index.html](https://www.elastic.co/guide/en/ecs/current/index.html)

ECS goes beyond security to let you know. It is the common way to do observability and other domains so if you want to you can do both application monitoring and security but for security the ultimate goal is to be able to do simpler searches for things like hosts, users, processes, etc... to get to information you need across different log files that have been parsed by your agents.

Also to let you know, you are not limited by what we ship as far as agents go. Our agents such as beats, endpoint agents, etc... are there and available as taking as much of the heavy intensive engineering work from analysts so they can focus on what they enjoy doing best which is coming up with interesting analysis techniques for their organizations or threat hunting. But we make these agents "extensible" so you can write your own modules for your own log files or you can always put together your own ECS documents by parsing your own log files using whatever programming languages you want to. Nothing stopping anyone. And since we use ECS, it will _just work_ with our UI and tooling as long as you adhere to the ECS documentation.

Now, to not get too much into the weeds as this is a very large broad topic, another component within our stack is usually a way to do analysis and then a way to begin incident response type workflows when you do see you have a security issue depending on your company policies and regulations.

For that we have timeline and cases:  
[https://www.elastic.co/guide/en/kibana/current/siem-ui.html#timelines-ui](https://www.elastic.co/guide/en/kibana/current/siem-ui.html#timelines-ui)  
[https://www.elastic.co/guide/en/siem/guide/current/cases-overview.html](https://www.elastic.co/guide/en/siem/guide/current/cases-overview.html)

Both of those features give you ways to do investigations and integrations with existing investigation tools depending on how your organization decides to do these things. But those tools are there to help with the centralized tooling for analyzing your organizations logs in the simplest ways we can think of that puts the power, flexibility, creativity and ultimately the organizational security responsibility into the analysts hands.

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [August 12, 2020, 4:28am UTC](https://discuss.elastic.co/t/what-siem-can-do/244483/3 "2020-08-12T04:28:38Z")

</div>

I am going to save this as a note and use this for future conversations when someone asks me what Elastic SIEM is!

---

<div class="post-metadata">

**Author:** ![syafeera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syafeera/32/47173_2.png) [@syafeera](https://discuss.elastic.co/u/syafeera)\
**Post date:** [August 13, 2020, 6:56am UTC](https://discuss.elastic.co/t/what-siem-can-do/244483/4 "2020-08-13T06:56:27Z")

</div>

Hi,

Thank you..i will read the blog articles..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2020, 6:56am UTC](https://discuss.elastic.co/t/what-siem-can-do/244483/5 "2020-09-10T06:56:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
