# 27 default Elastic Security rules contain definitions to non-existant indices and are broken

**URL:** <https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043>\
**Category:** Elastic Security\
**Created:** [April 22, 2022, 2:24pm UTC](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043 "2022-04-22T14:24:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [April 22, 2022, 2:24pm UTC](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043/1 "2022-04-22T14:24:30Z")

</div>

Hi there,  
As an example, the Elastic supplied default 'Endpoint Security' rule contains a hard coded definition to the index pattern 'logs-endpoint.alerts-\*' however, this index pattern does not exist and so this rule generates a warning.

I believe the rule should reference 'logs-endpoint.events.\*'.  
I created a duplicate rule and called it 'Endpoint Security Events' and referenced this index and it seems to work well.

There are a total of 27 rules which exhibit this type of warning, and therefore don't work, which is pretty worrying given they are the default supplied rules which ship with the product.

This problem exists in 8.1.2 and 8.1.3.

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [April 23, 2022, 2:20pm UTC](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043/2 "2022-04-23T14:20:15Z")

</div>

I think the best you can do is create an issue on the [Github repository](https://github.com/elastic/detection-rules) it will then be picked up by the maintainers

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [April 24, 2022, 9:48am UTC](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043/3 "2022-04-24T09:48:25Z")

</div>

Digging in to this a bit more it may be the case that these indices don't get created by Endpoint in the free tier, although the documentation is vague about this.

If someone from Elastic could verify this, it would be helpful.

---

<div class="post-metadata">

**Author:** ![Kevin\_Logan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_logan/32/74427_2.png) [@Kevin\_Logan](https://discuss.elastic.co/u/Kevin_Logan)\
**Post date:** [April 26, 2022, 2:03pm UTC](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043/4 "2022-04-26T14:03:28Z")

</div>

@finbarr996 - apologies for the delay in response.

The Security Endpoint will create these data streams for you in any tier, but there first needs to be deployed Endpoints streaming the appropriate data.

If you have deployed Endpoints, you're likely already streaming in many different types of Events and Metrics so you should see several existing data streams with the `logs-endpoint*` and `metrics-endpoint*` prefixes. You likely do not see the `logs-endpoint.alerts-*` data stream created because the Security Endpoints have not detected any malicious activity on your hosts, yet.

One way to generate an alert for testing (and to create the data stream) is to [download an EICAR test file](https://www.eicar.org/?page_id=3950) on to one of your hosts. When you access the file the Security Endpoint will generate an alert and stream it to ES. Then the `logs-endpoint.alerts-*` data stream will be created and the warning in the original rule will go away.

The default Endpoint Security rule that references `logs-endpoint.alerts-*` is the key rule that will promote Endpoint Security alerts so that they show up in your Alerts list. Be sure to re-enable it when using the EICAR file above.

Let me know if this helps or you have additional questions.

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [April 26, 2022, 3:10pm UTC](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043/5 "2022-04-26T15:10:30Z")

</div>

Hi Kevin,  
Thank you for your really conprehensive and helpful answer!  
The test worked and the index has been created. 🙂

Kind regards,  
John.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2022, 3:11pm UTC](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043/6 "2022-05-24T15:11:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
