# Detection Rule Error

**URL:** <https://discuss.elastic.co/t/detection-rule-error/252856>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [October 21, 2020, 2:41pm UTC](https://discuss.elastic.co/t/detection-rule-error/252856 "2020-10-21T14:41:06Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [October 27, 2020, 5:04am UTC](https://discuss.elastic.co/t/detection-rule-error/252856/6 "2020-10-27T05:04:26Z")

</div>

You could have more than one error going on. I did post that I found a mapping conflict between your custom one and the ECS signals mapping:

> [@Detections with custom query](https://discuss.elastic.co/t/detections-with-custom-query/252628/6):
>
> Hi @Anabella_Cristaldi, Appreciate the sample pray thank you! I do not see why is working for threshold but not for custom query (Does they have a different mechanism for quering)? Yes, they do have different mechanisms. The threshold one is an aggregation and it does not fill in all the values when it creates a signal. So, some good news is that in the soon to be released 7.10.0 where we improved error handling you will begin to see errors on that rule where before you were not. I just …

I would clean up the mappings around `host` and double check to ensure there aren't other conflicts and then from there we can see if you still have an issue on this one with the space name.

---

_[View the full topic](https://discuss.elastic.co/t/detection-rule-error/252856)._
