# Contact suricata and siem use cases

**URL:** <https://forum.suricata.io/t/contact-suricata-and-siem-use-cases/1373>\
**Category:** Help\
**Tags:** community\
**Created:** [May 17, 2021, 12:56pm UTC](https://forum.suricata.io/t/contact-suricata-and-siem-use-cases/1373 "2021-05-17T12:56:05Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![headfish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/headfish/32/275_2.png) [@headfish](https://forum.suricata.io/u/headfish)\
**Post date:** [May 17, 2021, 12:56pm UTC](https://forum.suricata.io/t/contact-suricata-and-siem-use-cases/1373/1 "2021-05-17T12:56:05Z")

</div>

Suricata was installed normally, and it is actually running on 1g network.  
However, since there is no SIEM yet, logs are being loaded into Elasticsearch.

I tried to use Elasticsearch for the first time, but there are so many limitations in creating a correlation with Elasticsearch, so I judge that I need to use another one (only some specific rules can be triggered. IP-based correlation is not possible.)

im currently looking at datadog, sumo logic, LogRhythm, etc. If you use it, can you tell how you are creating the correlation rules?
