@Donald S Hunter Jr Thanks for reaching out.
This forum is dedicated for Microsoft Azure services. We will be glad to answer Microsoft SIEM solution "Sentinel" queries.
Looking at your question for elastic SIEM setup, I think the following link can help you with setting up a lab SIEM solution on elastic SIEM :
https://unicornsec.com/home/siem-home-lab-series-part-1
https://logz.io/learn/complete-guide-elk-stack/
---------------------------------------------------------------------------------------------------------
Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.