# Alerts from prebuilt detection rules

**URL:** <https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633>\
**Category:** SIEM\
**Tags:** elastic-stack-alerting\
**Created:** [April 19, 2021, 10:31pm UTC](https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633 "2021-04-19T22:31:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![NightSpark](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@NightSpark](https://discuss.elastic.co/u/NightSpark)\
**Post date:** [April 19, 2021, 10:31pm UTC](https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633/1 "2021-04-19T22:31:24Z")

</div>

Hi,

I am running 7.12 and would like to send an alerts to slack whenever a positive match occurs on one of the prebuilt detection rules.  
i.e [Prebuilt rule reference | Elastic Security Solution [7.12] | Elastic](https://www.elastic.co/guide/en/security/current/prebuilt-rules.html)  
I can see that you can send an alert when rule is run or at regular intervals but not when triggered.

Is it possible to send the alert when this occurs and to bulk update all rules to do the same?

Thanks

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [April 20, 2021, 6:02pm UTC](https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633/2 "2021-04-20T18:02:11Z")

</div>

You can send alert to JIRA, Slack, Teams and etc, when rule is trigger

This is my creation for updating rules in bulk.  
[austinsonger/Elastic-Security (github.com)](https://github.com/austinsonger/Elastic-Security)

---

<div class="post-metadata">

**Author:** ![NightSpark](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@NightSpark](https://discuss.elastic.co/u/NightSpark)\
**Post date:** [April 21, 2021, 2:30am UTC](https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633/3 "2021-04-21T02:30:19Z")

</div>

Clever. Thanks that worked. Had to make a minor change to on curl from --raw-data to -d.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2021, 2:30am UTC](https://discuss.elastic.co/t/alerts-from-prebuilt-detection-rules/270633/4 "2021-05-19T02:30:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
