# Building block rules/use case

**URL:** https://discuss.elastic.co/t/building-block-rules-use-case/254737
**Category:** SIEM
**Created:** [November 9, 2020, 11:07am UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737 "2020-11-09T11:07:44Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 9, 2020, 11:07am UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/1 "2020-11-09T11:07:44Z")

</div>

Hi,

I am trying to understand the building block rules. Should we be able to create a rule that triggers if multiple building block rules trigger? If so how would I go about it?

Thanks  
Phil

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 9, 2020, 3:56pm UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/2 "2020-11-09T15:56:41Z")

</div>

I should add that so far i have used it to create multiple rules with a the prefix to the rule name then add a threshold rule with a query of signal.rule.name:prefix\*  
then look for host.name =\>2

Although building block rules are still appearing in detections when triggered despite the additional filter not been ticked. signal.rule.building\_block\_type: default withing the events

im on 7.9.2.

Thanks

---

<div class="post-metadata">

### Author: ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)
#### Post date: [November 9, 2020, 5:04pm UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/3 "2020-11-09T17:04:46Z")

</div>

Hey there @probson !

For your first issue of seeing the building block alerts in the UI - are you on the main detections page or on the rule details page? By default `Include building block alert` is not checked in the main page, but _is_ checked on the Rule Details page. I'm not sure if you are part of the Elastic Stack Community slack group? This [thread](https://elasticstack.slack.com/archives/CNRTGB9A4/p1602509622279400) could prove helpful.

> **[Slack](https://elasticstack.slack.com/?redir=%2Farchives%2FCNRTGB9A4%2Fp1602509622279400)**

You can indeed create a rule that triggers if multiple building block rules are triggered. When a rule is marked as a building block the `building_block_type` field set to the value `default`. From one of our [blogs](https://www.elastic.co/blog/whats-new-elastic-security-7-9-0-free-endpoint-security), it notes:

"You could, for example, use two building block rules — one configured to alert on abnormally high web server logins and the other configured to spot out-of-schedule maintenance activity on a database server — as inputs for a rule generating alerts that are more likely to merit analyst attention."

The example you gave of what you are doing in your second post seems about right. Has that been working for you?

Also, have you looked into EQL at all? I'm not familiar with your exact use case, but it could also be what you are looking for.

> **[EQL search | Elasticsearch Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql.html)**

Best,  
Yara

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 9, 2020, 5:42pm UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/4 "2020-11-09T17:42:59Z")

</div>

@yctercero

I was in the main detections page, i do not use slack but will check out the thread.

The example has worked for us, did not know if I was missing anything else.

I have not had a chance to look at EQL yet but with the upcoming changes i need to spend some time with it. The use case is mainly based around detections and KQL at the moment.

Thanks

---

<div class="post-metadata">

### Author: ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)
#### Post date: [November 9, 2020, 5:52pm UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/5 "2020-11-09T17:52:54Z")

</div>

The community slack is another great place to ask questions.

In the meantime though, I'm curious, if you fetch the mappings for you `.siem-signals` index what does it show for `building_block_type`? If you're unsure how to do that, you can check the mapping by going into the dev tools and running:

`GET /.siem-signals-[YOUR SPACE OR DEFAULT]/_mapping`

You should see it mapped to be "keyword". Is this what you see?

 ![Screen Shot 2020-11-09 at 12.51.45 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/0/60342579c51d550806855f2d66bda0cfa007e59d.jpeg)

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 9, 2020, 6:14pm UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/6 "2020-11-09T18:14:43Z")

</div>

> [@yctercero](#):
>
> GET /.siem-signals-[YOUR SPACE OR DEFAULT]/\_mapping

Hi,

I have checked and it is keyword.

Thanks

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 9, 2020, 6:16pm UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/7 "2020-11-09T18:16:20Z")

</div>

In fact thats for my cloud instance, i was testing building block with on prem. Will test building block in the cloud tomorrow and get back to you. Both are 7.9.2.

Thanks

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 10, 2020, 9:13am UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/8 "2020-11-10T09:13:40Z")

</div>

@yctercero  
Hi,

My on-prem setup does not have building\_block\_type in the template. This setup has been upgraded since around 7.2. We use logstash and occasionally point filebeat at kibana to update some of the dashboards and metricbeat to update that template.

The cloud solution was built straight to 7.9.2, this does have the keyword and tested this morning and the alert was not visible in the main detections UI.

Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 8, 2020, 9:13am UTC](https://discuss.elastic.co/t/building-block-rules-use-case/254737/9 "2020-12-08T09:13:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
