Elasticsearch Index Templates for SIEM Destinations
You need this page when you select Elasticsearch as the connector of a destination under Administration → System Settings → SIEM & Log Forwarding. Apinizer does not create the template for these indexes. The organization that owns the Elasticsearch cluster creates and manages it. See SIEM & Log Forwarding for the destination settings.
Connection Definition
Follow these rules for the Elasticsearch connection of a SIEM destination.
If you leave Cluster Administration turned on, Apinizer creates the ILM policy, the index template and the data stream of the API traffic log on this connection. SIEM documents do not contain @timestamp, so that data stream rejects every record. On a Legacy Raw destination, the loss is silent. On a v2 destination, the event counts as send_failed. Create the template, the ILM policy and the data stream with the commands on this page.
- Type: Select
ReadWrite. If you selectRead, Apinizer does not write. On a Legacy Raw destination, the loss is silent: Delivery Health stays green, and the error appears only in the application log. On a v2 destination, the event counts assend_failed. - Cluster Administration: Turn the switch Enable to administrate cluster off.
- Index Name: Enter the name of the data stream that you create below, for example
apinizer-siem-v2. A connection writes to one index only. Do not use the API traffic log index name (apinizer-log-apiproxy-...). Traffic records and SIEM records would mix. - One connection, one index: For Legacy Raw, create one connection and one destination for each stream (see the table below). For Schema v2, all streams share one envelope. One connection and one index are enough.
- Shared connections: Several destinations can use the same connection. Do not give the connection of a Legacy Raw destination to a v2 destination, because the mappings differ.