# Clarification on Rules execution

**URL:** <https://discuss.elastic.co/t/clarification-on-rules-execution/368073>\
**Category:** Elastic Security\
**Created:** [October 1, 2024, 8:26am UTC](https://discuss.elastic.co/t/clarification-on-rules-execution/368073 "2024-10-01T08:26:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Maxim\_Palenov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxim_palenov/32/122504_2.png) [@Maxim\_Palenov](https://discuss.elastic.co/u/Maxim_Palenov)\
**Post date:** [October 3, 2024, 10:26am UTC](https://discuss.elastic.co/t/clarification-on-rules-execution/368073/2 "2024-10-03T10:26:28Z")

</div>

Hi @abubacker, thanks for the question and using Elastic Security!

Spaces is Kibana's feature. Elasticsearch doesn't know anything about spaces. It just stores Kibana's data like installed rules per space and source events data.

While rules could be installed in each space individually rule's index pattern doesn't depend on space by default. It means that rules will read the same source data from specified index patterns. For example having a prebuilt rule installed in different spaces and enabled with `logs-*` index pattern we'll get the same generated alerts since it will read the same source data. You might check out a [similar question](https://discuss.elastic.co/t/kibana-security-elastic-rules-space-issue/301861) on how to split source data and rules per space.

Permissions are handled by Elasticsearch per user. Space information doesn't take any action in that.

> Same scenario for ML jobs ?

It works the same way for ML jobs.

---

_[View the full topic](https://discuss.elastic.co/t/clarification-on-rules-execution/368073)._
