Troubleshooting
Dashboard Not Loading
Check your browser’s console for JavaScript errors.
Verify your user has permissions for SIEM dashboards.
Try refreshing the page or clearing browser cache.
Check if the time range is too large — reduce to last 24 hours.
No Data Showing
Verify Endpoint Security agents are connected and reporting — check agent status in the SIEM Overview dashboard.
Confirm the selected time range includes the period when events occurred.
Check if filters are too restrictive.
Verify your user role has access to the relevant data sources.
Alerts Not Triggering
Alerts Not Firing
Diagnostic steps:
Check rule syntax - Verify YAML rule definition syntax.
Test with smaller dataset - Use Discover to test query logic.
Verify index patterns - Ensure data exists in specified indices.
Check time ranges - Confirm events fall within detection window.
Review logs - Check ELS logs for processing errors.
High False Positive Rate
Solutions:
Tune alert thresholds - Increase event counts or severity levels.
Add exclusions - Filter out known good activities.
Refine time windows - Adjust detection time frames.
Use risk scoring - Focus on high-risk events only.
Performance Issues
Reduce dashboard time ranges to improve loading speed.
Use filters to limit data volume.
Close unused dashboard tabs.
Contact administrator if cluster performance is degraded.