# Cannot filter data in elastic SIEM

**URL:** <https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124>\
**Category:** SIEM\
**Created:** [October 15, 2020, 2:44am UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124 "2020-10-15T02:44:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [October 15, 2020, 2:44am UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124/1 "2020-10-15T02:44:33Z")

</div>

Hi all  
I have a problems in the elastic siem.  
The filter function for me when i tried to filter for some field in the rule that i have created. those field seems to be not recognized by elastic so they do not allow me to filter those data. event though i have tried to create the index pattern and still the data is not recognized.  
Is there a way to make siem understand those data since i really need to filter those data out.

Thanks for your time.

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [October 15, 2020, 2:17pm UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124/2 "2020-10-15T14:17:02Z")

</div>

HI there @lusynda!

Would you be willing to provide a little more detail around the filter you're seeing not take effect? When you say you tried to filter for some field in the rule that you created, do you mean you're not seeing the rule create any alerts with this filter? Do you see any errors under the `Failure History` tab on the Rule Details page / the `Monitoring` tab on the main Rules page, or is the rule running successfully? Are you seeing the query + filter work within Discover? What type of Rule are you trying to create, and did you ensure the correct index pattern is specified in the first step? Also, what version do you happen to be running?

With the above information we should be better able to help identify why your filters aren't working. 🙂

Thanks!  
Garrett

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [October 16, 2020, 4:46am UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124/3 "2020-10-16T04:46:03Z")

</div>

@spong thanks for your responce,

- the "Add filter" button under custom query is not working for me in SIEM and only SIEM, and it seem i misinform you on th not working thing, it's not that is not working, but it no longer have any suggestion on the field to filter on any more so i cannot use it.
- The rule still gen alert and there are no failure for the rule.
- the index patterns is correct since when i created the rule there are still alert for it.
- all type of rule have this problems.
- Some time i see the `Unexpected token < in JSON at position 0` in SIEM and only SIEM part of the system.

---

<div class="post-metadata">

**Author:** ![AngelaChuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelachuang/32/49719_2.png) [@AngelaChuang](https://discuss.elastic.co/u/AngelaChuang)\
**Post date:** [October 16, 2020, 3:02pm UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124/4 "2020-10-16T15:02:12Z")

</div>

Hello @lusynda,

Does it mean that you don't have the suggestions after putting the filter field?

 ![Screenshot 2020-10-16 at 15.41.54](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15590447d49b6c4b1f66d028a7e227b18fc16687.png)

Could you please check if the index patterns you are using exists in Stack Management / index patterns?  
Not sure if this reproduced your case, but I found that if I left an index pattern which does not exist, I'll have no suggested fields available.

 ![Screenshot 2020-10-16 at 15.58.51](https://us1.discourse-cdn.com/elastic/original/3X/7/5/759e331e4f8aa58dd028370413413865de9dbcd8.png)

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [October 17, 2020, 2:51am UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124/5 "2020-10-17T02:51:03Z")

</div>

Yes well like i said when i create the rule for it. It still generate alert for me so the index patterns is corrected. So the index pattern does exsist.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [October 20, 2020, 10:47pm UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124/6 "2020-10-20T22:47:29Z")

</div>

If you're on plain version of 7.9.0, I would consider upgrading to the latest 7.9.2 as we implemented several performance enhancements which makes getting the fields magnitudes faster. I think from your error description you're timing out getting the fields. This can happen if you have a _lot_ of different indexes or one of your indexes has a "mapping explosion" where it has a _lot_ of fields that are auto-generated or just a lot in general.

The two tickets we fixed for 7.9.1+ with regards to perf here:

> <https://github.com/elastic/kibana/pull/75716>

  

> <https://github.com/elastic/kibana/pull/75718>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2020, 10:47pm UTC](https://discuss.elastic.co/t/cannot-filter-data-in-elastic-siem/252124/7 "2020-11-17T22:47:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
