# DataStream vs detection rules

**URL:** <https://discuss.elastic.co/t/datastream-vs-detection-rules/261563>\
**Category:** Elastic Security\
**Tags:** datastreams\
**Created:** [January 19, 2021, 3:01pm UTC](https://discuss.elastic.co/t/datastream-vs-detection-rules/261563 "2021-01-19T15:01:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles100](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles100/32/82544_2.png) [@Charles100](https://discuss.elastic.co/u/Charles100)\
**Post date:** [January 19, 2021, 3:01pm UTC](https://discuss.elastic.co/t/datastream-vs-detection-rules/261563/1 "2021-01-19T15:01:03Z")

</div>

Hi, I'm testing datastreams right now and observed that default detection rules are not looking logs from my datastreams indices. Do I have to manually change all default rules (and new ones added by updates) to include the auto-generated indices created by datastreams (.ds-\*) ?

Thank you

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [January 20, 2021, 4:08pm UTC](https://discuss.elastic.co/t/datastream-vs-detection-rules/261563/2 "2021-01-20T16:08:07Z")

</div>

Are these your own custom data stream logs? The default rules are looking at different indexes, so they're not all going to be the same. If so, yeah, you will have to edit and change them. You can do this via the UI or you if you're handy with scripting we have a REST API you can use to automate some of these types of tasks:

> **[Update rule | Elastic Security Solution \[7.10\] | Elastic](https://www.elastic.co/guide/en/security/current/rules-api-update.html)**

We are looking at ways of improving things such as changing indexes globally or overriding them for rules but we don't have a global mechanism at the this point.

---

<div class="post-metadata">

**Author:** ![Charles100](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles100/32/82544_2.png) [@Charles100](https://discuss.elastic.co/u/Charles100)\
**Post date:** [January 21, 2021, 5:32am UTC](https://discuss.elastic.co/t/datastream-vs-detection-rules/261563/3 "2021-01-21T05:32:29Z")

</div>

Hi Franck, yes they are custom data streams. So for the moment, I guess I can name my datastreams with the same syntax that what detection rules are looking for (ex: filebeat-\*) and detections will magically work.

Thx !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:22am UTC](https://discuss.elastic.co/t/datastream-vs-detection-rules/261563/4 "2022-11-04T08:22:00Z")

</div>


