# Detect Rules

**URL:** <https://discuss.elastic.co/t/detect-rules/312889>\
**Category:** Endpoint Security\
**Tags:** detection-rules\
**Created:** [August 25, 2022, 8:54am UTC](https://discuss.elastic.co/t/detect-rules/312889 "2022-08-25T08:54:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![VitorBarroso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitorbarroso/32/99187_2.png) [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Post date:** [August 25, 2022, 8:54am UTC](https://discuss.elastic.co/t/detect-rules/312889/1 "2022-08-25T08:54:47Z")

</div>

How i "connect" my detect rules with my events on External alert trend?  
My detect rules are those i load from the system.

---

<div class="post-metadata">

**Author:** ![Pedro\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pedro_jaramillo/32/45904_2.png) [@Pedro\_Jaramillo](https://discuss.elastic.co/u/Pedro_Jaramillo)\
**Post date:** [September 7, 2022, 6:36pm UTC](https://discuss.elastic.co/t/detect-rules/312889/2 "2022-09-07T18:36:47Z")

</div>

Hi @VitorBarroso, you can follow the steps in our [documentation](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rules-ui-create) to create detection rules configured to look for external event data. For example, you could create a "Custom Query" rule that searches for source data matching `event.kind: "alert"`. Typically, events that appear in the External alert trend graph have an "event.kind" value of "alert".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2022, 6:37pm UTC](https://discuss.elastic.co/t/detect-rules/312889/3 "2022-10-05T18:37:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
