# Where does the SIEM saved objects reside?

**URL:** <https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330>\
**Category:** SIEM\
**Created:** [July 15, 2020, 3:56pm UTC](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330 "2020-07-15T15:56:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 15, 2020, 3:56pm UTC](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330/1 "2020-07-15T15:56:14Z")

</div>

hi  
I was looking into to find

1. Which all index-patterns SIEM app looks by default? How to modify this to include more indices?
2. Where are the saved-objects reside? I was trying to find the objects as per the [example doc](https://github.com/elastic/examples/blob/master/Security%20Analytics/SIEM-examples/Detections-API/Kibana.postman_collection.v2.json), but some of them are not working.

---

<div class="post-metadata">

**Author:** ![brian\_m](https://avatars.discourse-cdn.com/v4/letter/b/848f3c/32.png) [@brian\_m](https://discuss.elastic.co/u/brian_m)\
**Post date:** [July 15, 2020, 5:00pm UTC](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330/2 "2020-07-15T17:00:18Z")

</div>

I don't know the answer to 2., but for 1., you can change what indexes the SIEM app looks for in the Kibana Advanced Settings (Under the Stack Management section in 7.8), in the SIEM section. The defaults it shows are:

"apm-\*-transaction\*, auditbeat-\*, endgame-\*, filebeat-\*, packetbeat-\*, winlogbeat-\*"

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 15, 2020, 6:23pm UTC](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330/3 "2020-07-15T18:23:21Z")

</div>

@brian_m cheers for the advanced settings and upvoted.

Will wait to see where the "saved-objects" reside too before I mark it as the solution

---

<div class="post-metadata">

**Author:** ![stephmilovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephmilovic/32/146835_2.png) [@stephmilovic](https://discuss.elastic.co/u/stephmilovic)\
**Post date:** [July 15, 2020, 10:09pm UTC](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330/4 "2020-07-15T22:09:45Z")

</div>

Hi @kelk. Do you mean where do your detections saved objects live? You can use those queries in the example doc to query for your signals index, `curl -X GET \ https://yourkibanainstance.com/api/detection_engine/index \` + credentials. Signal indices are created for each Kibana space. The naming convention is: `.siem-signals-<space name>` . For the default space, the signals index is named `.siem-signals-default` .

If you're looking for the output of signals and data, that example doc is the CURL you can use and you will get your data back from the siem signals index. The rules themselves are stored as a layer on top of saved objects. You can get to those using the detections API curl command but they're ultimately stored in the .kibana index in case you are just trying to understand saved object.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2020, 10:20pm UTC](https://discuss.elastic.co/t/where-does-the-siem-saved-objects-reside/241330/5 "2020-08-12T22:20:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
