diff --git a/docs/siem/index.asciidoc b/docs/siem/index.asciidoc index c947e000c8138..f56baf6abdc2e 100644 --- a/docs/siem/index.asciidoc +++ b/docs/siem/index.asciidoc @@ -24,7 +24,7 @@ Kibana provides step-by-step instructions to help you add data. The detailed information and instructions. [float] -=== {Beats} +=== {Beats} https://www.elastic.co/products/beats/auditbeat[{auditbeat}], https://www.elastic.co/products/beats/filebeat[{filebeat}], @@ -33,9 +33,14 @@ https://www.elastic.co/products/beats/packetbeat[{packetbeat}] send security events and other data to Elasticsearch. The default index patterns for SIEM events are `auditbeat-*`, `winlogbeat-*`, -`filebeat-*`, and `packetbeat-*``. You can change the default index patterns in +`filebeat-*`, `endgame-*`, and `packetbeat-*``. You can change the default index patterns in *Kibana > Management > Advanced Settings > siem:defaultIndex*. +[float] +=== Elastic Endpoint Sensor Management Platform + +The Elastic Endpoint Sensor Management Platform (SMP) ships host and network events directly to the SIEM application, and is fully ECS compliant. + [float] === Elastic Common Schema (ECS) for normalizing data