# Detection rule kquery will not trigger but the query match

**URL:** <https://discuss.elastic.co/t/detection-rule-kquery-will-not-trigger-but-the-query-match/273085>\
**Category:** SIEM\
**Created:** [May 15, 2021, 3:59pm UTC](https://discuss.elastic.co/t/detection-rule-kquery-will-not-trigger-but-the-query-match/273085 "2021-05-15T15:59:03Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![aditi\_salunke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aditi_salunke/32/85600_2.png) [@aditi\_salunke](https://discuss.elastic.co/u/aditi_salunke)\
**Post date:** [May 29, 2021, 4:56pm UTC](https://discuss.elastic.co/t/detection-rule-kquery-will-not-trigger-but-the-query-match/273085/3 "2021-05-29T16:56:33Z")

</div>

Hi @Mike_Paquette @leon3

I am facing kinda same issue. Can you please help

Here is the link of issue:

> [@Detection rules which are based on indices where host field is fetched as string are not generating the alerts](https://discuss.elastic.co/t/detection-rules-which-are-based-on-indices-where-host-field-is-fetched-as-strong-are-not-generating-the-alerts/274406):
>
> Bulk Indexing of signals failed: object mapping for [host] tried to parse field [host] as object, but found a concrete value name: "\<rule name\>:\<random id\>" rule id: "\<rule\_id\>" signals index: ".siem-signals-default" So above reason we are getting in 'failure history' of some rules Though the query is triggering alerts in preview while creating rule after activation it's not triggering any alerts Things which i found might be concern: In X index, mapping is dynamic, host field is present i…

---

_[View the full topic](https://discuss.elastic.co/t/detection-rule-kquery-will-not-trigger-but-the-query-match/273085)._
