# Correlation rules not working

**URL:** <https://discuss.elastic.co/t/correlation-rules-not-working/271147>\
**Category:** SIEM\
**Tags:** elastic-stack-alerting\
**Created:** [April 24, 2021, 2:35pm UTC](https://discuss.elastic.co/t/correlation-rules-not-working/271147 "2021-04-24T14:35:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nil\_Battey\_Sannata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nil_battey_sannata/32/87040_2.png) [@Nil\_Battey\_Sannata](https://discuss.elastic.co/u/Nil_Battey_Sannata)\
**Post date:** [April 24, 2021, 2:35pm UTC](https://discuss.elastic.co/t/correlation-rules-not-working/271147/1 "2021-04-24T14:35:46Z")

</div>

I was trying to test some of the prebuilt elastic detection rules with my Beat-Elasticsearch-Kibana setup. All other rules with simple query was working but the rules with event correlation was not working. I tried all possible troubleshooting and research but couldn't get to the conclusion.

Below is the query I was trying to test with required data from winlogbeat, sysmon.  
query = '''  
registry where event.type in ("creation", "change") and  
registry.path : ("HKLM\SYSTEM\_ControlSet_\Control\Print\Monitors\_",  
"HLLM\SYSTEM\ControlSet\Control\Print\Environments\Windows_\Print Processors\_") and  
registry.data.strings : "_.dll" and  
/\* exclude SYSTEM SID - look for changes by non-SYSTEM user \*/  
not user.id : "S-1-5-18"

My setup- Winlogbeat-Elasticsearch-Kibana.

Can someone please help here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2021, 2:36pm UTC](https://discuss.elastic.co/t/correlation-rules-not-working/271147/2 "2021-05-22T14:36:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
