# Anybody successfully created a detection rule for Red Hat security updates

**URL:** <https://discuss.elastic.co/t/anybody-successfully-created-a-detection-rule-for-red-hat-security-updates/377446>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [April 23, 2025, 2:17pm UTC](https://discuss.elastic.co/t/anybody-successfully-created-a-detection-rule-for-red-hat-security-updates/377446 "2025-04-23T14:17:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [April 23, 2025, 2:17pm UTC](https://discuss.elastic.co/t/anybody-successfully-created-a-detection-rule-for-red-hat-security-updates/377446/1 "2025-04-23T14:17:52Z")

</div>

I read that is is possible to create a detection rule to alert if there are security updates required on a Red Hat or CentOS box (we use RHEL for production, CentOS for testing).

I came across the following "query" but apparently I don't have things configured to access some of the values:

`(system.os.name: "Red Hat" OR system.os.name: "CentOS") AND system.package.updates: >0 AND system.package.update.type: "security"`

I don't appear to have system.os or system.package.

I would greatly appreciate it if anybody has accomplished this and is willing to share insight, or if someone knows an accurate resource they can point me to.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [May 9, 2025, 10:58am UTC](https://discuss.elastic.co/t/anybody-successfully-created-a-detection-rule-for-red-hat-security-updates/377446/2 "2025-05-09T10:58:02Z")

</div>

There must be an integration added, beat running on the target machines producing documents with such content.

Did the query indicate required integration?

I think such objective can be achieved with

> **[Osquery Manager integration | Elastic Documentation](https://www.elastic.co/docs/reference/integrations/osquery_manager)**
>
> With this integration, you can centrally manage Osquery deployments to Elastic Agents in your Fleet and query host data through distributed SQL. This...

You can create a scheduled query to probe for available system updates.
