# Detection Rules Integration Dependencies

**URL:** <https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822>\
**Category:** SIEM\
**Created:** [October 15, 2024, 7:33am UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822 "2024-10-15T07:33:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 15, 2024, 7:33am UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822/1 "2024-10-15T07:33:20Z")

</div>

Hi,  
We experience some issues with detection rules detecting their dependencies on installed integrations correctly:

a) Installed Integrations are displayed as "Disabled" complaining there would be no agent policies using it. We have to edit any already configured policy, change anything in the allegedly disabled integration configuration to be able to save the changed settings -\> then the rules correctly recognize the integration as "Installed" again.

b) the "Windows" Integration always shows this "version mismatch" (Screenshot):  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/581e525c1ccbcf3bb3e7fa08c68ae4f4998eaee6.png)

It seems that these are only "cosmetical" issues because the rules work just fine with the collected data and produce alerts based on the indices of the wrongly "Disabled" or otherwise faulty recognized integrations. Nevertheless it's annoying to have no reliable indicator if all prerequisites of a rule are satisfied or not...

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2024, 12:10pm UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822/2 "2024-10-15T12:10:11Z")

</div>

Hello,

Which version of the stack are you using?

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 15, 2024, 12:36pm UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822/3 "2024-10-15T12:36:28Z")

</div>

sorry for not mentioning from start: 8.15.2, on-prem, debian-based

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2024, 12:42pm UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822/4 "2024-10-15T12:42:23Z")

</div>

There was an issue about it, but it was marked as solved a long time ago.

It is this one: [[Security Solution] Prebuilt rules' Related Integrations: version mismatch · Issue #139440 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/139440)

I would comment there and say that it stills happen on 8.15.2

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 16, 2024, 12:49pm UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822/5 "2024-10-16T12:49:37Z")

</div>

Thanks for your suggestion @leandrojmp but the topic was closed as completed in 2022 and I don't want to participate/reopen this using my personal git hub-account.

I'll stick with my workaround:

If anyone else encounters similar phenomenona - installed and enabled integrations appear as "Disabled" or with version mismatches that should be solved long ago:  
in any agent-policy containing the integration -\>  
edit it,  
change something,  
save the changed settings (and change it all back) -\>  
your detection rules should update their view of dependent integrations now  
(at least this works on 8.15.x Kibana-Versions, prebuilt-rules integration version 8.15.8, debian based installation, on premises, not containerized).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2024, 12:50pm UTC](https://discuss.elastic.co/t/detection-rules-integration-dependencies/368822/6 "2024-11-13T12:50:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
