Description

This Kibana dashboard example is visualizing the results of the Elastic SIEM detection engine. We also have a similar version of this dashboard using Kibana canvas. The Elastic SIEM detection engine is a great way to analyze all the cybersecurity related data you have stored in your Elastic Security installation. You can use it for your SIEM related as well as for your Elastic Endpoint related data.

The idea of the dashboard is to highly aggregate the results of the detection engine. Every alert that is created by the detection engine is a possible threat. However there can be many of them depending on the amount and criticality of systems you observe. Being able to get these results, aggregating and visualizing it even further than the Elastic Stack is doing it OOTB is one of the big strength that the Elastic Stack has. However getting to this point as a new user takes some time.

This Kibana dashboard will help you to identify threats and observe the results of the detection engine from day 1.

What is the Elastic SIEM detection engine?

The detection engine provides SOC teams with a complete SIEM rule experience within the free Elastic SIEM. The detection engine draws from a purpose-built set of Elasticsearch analytics engines and runs on a new distributed execution platform in Kibana.

Prebuilt rules

Rules can be difficult to develop and require a lot of time to test. Therefore, the detection started with a lot of prebuilt rules developed by Elastic Security’s intelligence and analysis team and has been widely used in Elastic’s production environment. New rules to respond to the latest critical threats are constantly being developed. Getting them loaded and ready to run is as simple as clicking a button! Using the Elastic content share you can also load a big chunk of detection rules next to the ones delivered by Elastic.

Tested versions 7.13
ECS compliant Yes

You must log in to submit a review.

Related downloads

Azure billing data network

A vega visualization that shows the connection between resource group, resource type and the resource itself based on Elastic agent azure billing data integration.

osquery performance dashboard

Kibana Dashboard example to visualize osquery performance

APM Services overview canvas

Average rating:

An adaptive turn key canvas example based on Elastic APM data.

CMDB dependency in Kibana Dashboard

Kibana vega example to show how to load visualize relationships between different infrastructure and network components in vega.

Resource Optimization Dashboard

Elastic Resource Optimization Dashboard to seamlessly integrate APM insights with cloud cost data for actionable resource management and cost-saving strategies

Vega Compound Gauge

This is a compund gauge visualization made with Vega. Its very helpful for visualization of percentage values.

These downloads could be also interesting for you

OpenSIEM Logstash Parsing

Logstash Parsing Configurations for Elastic SIEM parses many different sources into ECS

Azure billing data network

A vega visualization that shows the connection between resource group, resource type and the resource itself based on Elastic agent azure billing data integration.

Kubernetes architecture overview

Vega visualization to show the dependencies between the different Kubernetes components in a single visualization

Sigma Elastic SIEM rules for web server logs

A collection of rules based on the Sigma detection rules for web server looks, e.g. apache, nginx or IIS.

Sigma AWS Cloudtrail Detection rules

A collection of rules based on the Sigma rules for AWS based on the Filebeat AWS module and Elastic agent integration.

Ask Me Anything Booth – Canvas Example

This is an example canvas page that shows how to visualize using canvas in general.