# Detection Custom Rule not working

**URL:** <https://discuss.elastic.co/t/detection-custom-rule-not-working/269578>\
**Category:** SIEM\
**Tags:** elastic-stack-alerting, detection-rules\
**Created:** [April 8, 2021, 10:16am UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578 "2021-04-08T10:16:21Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![anaghadeoreofficial](https://avatars.discourse-cdn.com/v4/letter/a/bbce88/32.png) [@anaghadeoreofficial](https://discuss.elastic.co/u/anaghadeoreofficial)\
**Post date:** [April 8, 2021, 10:16am UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/1 "2021-04-08T10:16:21Z")

</div>

![error](https://us1.discourse-cdn.com/elastic/original/3X/6/5/6558d2dd5f16ebe71695ea05f107f24a33ddc852.png)

We are unable to view custom alerts in the detection module. Showing error as below:

![Error2](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36c232278dcb40b6a2415613a24bcdafb1a04b30.png)

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [April 12, 2021, 8:59pm UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/2 "2021-04-12T20:59:56Z")

</div>

Hey there @anaghadeoreofficial -- welcome to the community! 👋

Not sure what version you're on, but if you're below `7.12`, there's a chance it could be [this issue](https://github.com/elastic/kibana/issues/93325), where a rule with invalid fields is preventing the table from loading. Have you by chance used the `Import rule` functionality to import any custom or modified rules? The error itself points towards a potentially invalid query `filter` on the rule, so that would be suspect.

If it is indeed the above issue, recovery steps at this point would be to delete the problem rule. You should be able to do this via the [Alerts and Actions UI](https://www.elastic.co/guide/en/kibana/7.12/managing-alerts-and-actions.html) under Stack Management, or leveraging the [Detections API](https://www.elastic.co/guide/en/security/current/rule-api-overview.html).

Note: the Alerts and Actions UI was not designed to for managing Security Detection Rules, however it should suffice for this as it has less strict validation when returning results.

If this turns out not to be your issue, could you please provide more information about your deployment (version, hosting, etc), and rules you're using?

Hope this helps -- cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [April 12, 2021, 10:00pm UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/3 "2021-04-12T22:00:20Z")

</div>

Chatted a bit with @Frank_Hassanabad, and upon further inspection this doesn't appear to be related to [#93325](https://github.com/elastic/kibana/issues/93325). This is an ES error bubbling up, similar to this [other recent discuss](https://discuss.elastic.co/t/failed-to-fetch-rules-and-timelines-failed-to-parse-field-filter-x-content-parse-exception/269624).

Can you verify the following?

- Are you seeing this error on any other pages within Kibana? Does navigating to `Stack Monitoring` show this error?
- What version and type of deployment are you on?
- Can you share the current user's role definition, and any configured document level security options that may be present?
- Did this start happening after a specific configuration change, or addition of new rules? If so, can you provide more details as to what changes, or the rules in question?

We should be able to debug further with the above information -- thanks!

Garrett

---

<div class="post-metadata">

**Author:** ![anaghadeoreofficial](https://avatars.discourse-cdn.com/v4/letter/a/bbce88/32.png) [@anaghadeoreofficial](https://discuss.elastic.co/u/anaghadeoreofficial)\
**Post date:** [April 14, 2021, 5:50am UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/4 "2021-04-14T05:50:03Z")

</div>

Hey, @spong as you mentioned above, YES I am seeing this error in the Stack monitoring section also.  
-Our deployment is on-premises and we are using version --\> Kibana version 7.11  
-I am having a superuser role access which concludes that having all privileges for Elastic clusters, indices, and kibana spaces.  
-Also yes we activate around 200 prebuild elastic rules in bulk and after that, we are facing these kinds of errors in detection rule and stack monitoring.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 14, 2021, 3:38pm UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/5 "2021-04-14T15:38:53Z")

</div>

> [@spong](#):
>
> Can you share the current user's role definition, and any configured document level security options that may be present?

Can you look in there. We are suspicious that you have a filter or something set within the

```auto
roles -> Granted documents query

```

 ![Screen Shot 2021-04-14 at 9.36.49 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d2c146020c266255183f26f2d36dc00107f939e4.png)

Or as a global index alias level. The stack monitoring is pretty separate from the security solutions application which hints at maybe something global happening where an additional filter or query is being attached when you are querying for some information.

---

<div class="post-metadata">

**Author:** ![anaghadeoreofficial](https://avatars.discourse-cdn.com/v4/letter/a/bbce88/32.png) [@anaghadeoreofficial](https://discuss.elastic.co/u/anaghadeoreofficial)\
**Post date:** [April 15, 2021, 8:26am UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/6 "2021-04-15T08:26:07Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4cb11946f7d5a63518c64875ff7b8f70075a3208.png)  
We do have this default permission for the superuser role.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 19, 2021, 4:56pm UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/7 "2021-04-19T16:56:03Z")

</div>

Huh, we haven't seen something like this before since this is effecting stack monitoring and detection engine.

This is very unusual.

If you're not on the latest 7.11.2 I would upgrade to that or even maybe to 7.12.0. That might help things out. If it doesn't help, within both stack monitoring and detection rules can you open up the network panel in chrome and give us the errors from there? As much of the network errors we can have such as the API path, response, etc... would help us figure out why a few people are seeing this problem.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 29, 2021, 3:41pm UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/8 "2021-04-29T15:41:18Z")

</div>

From other conversations this was solved through:

```auto
There was version compability issue between elasticsearch(v12) and kibana(v10).
Upgrading the kibana solved all the issues.

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2021, 3:41pm UTC](https://discuss.elastic.co/t/detection-custom-rule-not-working/269578/9 "2021-05-27T15:41:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
