# Detection Rule Error

**URL:** <https://discuss.elastic.co/t/detection-rule-error/252856>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [October 21, 2020, 2:41pm UTC](https://discuss.elastic.co/t/detection-rule-error/252856 "2020-10-21T14:41:06Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [October 23, 2020, 10:10am UTC](https://discuss.elastic.co/t/detection-rule-error/252856/5 "2020-10-23T10:10:05Z")

</div>

Hi @Frank_Hassanabad,

The sample data and mappings are the same posted in [Detections with custom query](https://discuss.elastic.co/t/detections-with-custom-query/252628/4)

Regarding to kibana logs, the error that appear is:

`{"type":"log","@timestamp":"2020-10-21T14:16:06Z","tags":["error","plugins","securitySolution","plugins","securitySolution"],"pid":6587,"message":"[-] search_after and bulk threw an error TypeError: Cannot read property 'some' of undefined name: \"Rogue AP Detection\" id: \"376e5caf-7fa0-4657-87b5-33ee249f9b3b\" rule id: \"b57a7041-d90f-4023-adf4-09e19182dcea\" signals index: \".siem-signals-siem\""}`

But I still believe that is something related to the space name (siem). In the new space (temp) I did not have any errors.

Thank you  
Regards  
Anna

---

_[View the full topic](https://discuss.elastic.co/t/detection-rule-error/252856)._
