# Creating alert when event didn't occur

**URL:** <https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [August 23, 2021, 7:20am UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195 "2021-08-23T07:20:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marduuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marduuk/32/93562_2.png) [@Marduuk](https://discuss.elastic.co/u/Marduuk)\
**Post date:** [August 23, 2021, 7:20am UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195/1 "2021-08-23T07:20:13Z")

</div>

Hey,  
For past few days I have been trying to create a rule that will trigger when something doesn't happen. So let's say we have two executables, `malware.exe` and `antivirus.exe`. I want to write a rule that would trigger an alert when `malware.exe` process is run and, within next hour, `antivirus.exe` is not run. I thought of many ways of doing it but no luck. Anyone got an idea how this can be achieved?

Cheers!

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [August 23, 2021, 3:22pm UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195/2 "2021-08-23T15:22:59Z")

</div>

It's not perfect, but the closest thing that comes to mind for me is EQL `until` ([docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql-syntax.html#eql-until-keyword)).

Basically it works like this:

```auto
sequence
  [< A: the first thing that must happen >]
  [< C: the third thing that must happen >]
until
  [< B: the second thing that should not happen >]

```

Basically how it works, is that it looks for A followed by C, and if B happens in between then the sequence is invalid and will not generate an alert. I'm not totally sure if this fits well with your use case, but it might be worth a shot.

One way we've used it before is like this, to watch out for pid reuse. This example query stops tracking when a termination is seen, that way it won't match across a reused process ID.

```auto
sequence by process.pid
  [process where < creation >]
  [network where < connect >]
until
  [process where <termination>]

```

There might options at your disposal, and this is just what I'm most familiar with. Hope this is a start!

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [August 23, 2021, 3:25pm UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195/3 "2021-08-23T15:25:07Z")

</div>

Your sequence might look something like

```auto
sequence with maxspan=1h
  [process where process.name : "malware.exe"] 
  [< unsure what goes here, if you have something that reliably kicks off after? >]
until
  [process where process.name : "antivirus.exe"]

```

---

<div class="post-metadata">

**Author:** ![Marduuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marduuk/32/93562_2.png) [@Marduuk](https://discuss.elastic.co/u/Marduuk)\
**Post date:** [August 23, 2021, 5:38pm UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195/4 "2021-08-23T17:38:06Z")

</div>

Hey Ross, thanks for reply! 🙂  
I tried it this way. We kinda need something like `not until`.  
Basically, if A is followed by a C and B doesn't happen I want to generate an alert. The problem is that B event is not present.  
I'm trying to generate an alert for `malware.exe` after which `antivirus.exe` process didn't start.

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [August 23, 2021, 5:56pm UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195/5 "2021-08-23T17:56:14Z")

</div>

I _think_ `until` is still what you want.

```auto
sequence
  [A]
  [C]
until
  [B]

```

If `B` **does** exist between `A` and `C` then you **don't** get an alert for `[A, C]`.  
If `B` **does not** exist between `A` and `C` then you **do** get an alert for `[A, C]`.

I'm just not sure what your `C` is.

---

<div class="post-metadata">

**Author:** ![Marduuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marduuk/32/93562_2.png) [@Marduuk](https://discuss.elastic.co/u/Marduuk)\
**Post date:** [August 24, 2021, 5:44am UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195/6 "2021-08-24T05:44:46Z")

</div>

Yup it's a good way I see it now, but, still not really working, I don't have any C sadly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2021, 5:45am UTC](https://discuss.elastic.co/t/creating-alert-when-event-didnt-occur/282195/7 "2021-09-21T05:45:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
