# Detection Rules Update Failure

**URL:** <https://discuss.elastic.co/t/detection-rules-update-failure/369051>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [October 18, 2024, 9:54am UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051 "2024-10-18T09:54:06Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 18, 2024, 9:54am UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/1 "2024-10-18T09:54:06Z")

</div>

Hi,

With version 8.15.3 we see 18 prebuilt security detection rules failing to update (Screenshot):  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/2/220db7b222db46dabd8415a100d61147f5be53e1.png)

List of rules not being able to update:

```auto
Anomalous Windows Process Creation
Suspicious Windows Process Cluster Spawned by a User
Unusual Windows Username
Unusual Windows Service
Suspicious Powershell Script
Unusual Windows User Privilege Elevation Activity
Unusual Windows Remote User
Unusual Process Spawned by a User
Unusual Windows Path Activity
Unusual Process Spawned by a Host
Unusual Process For a Windows Host
Anomalous Process For a Windows Population
Unusual Windows Process Calling the Metadata Service
Unusual Windows Network Activity
Suspicious Windows Process Cluster Spawned by a Host
Unusual Windows User Calling the Metadata Service
Unusual Process Spawned by a Parent Process
Suspicious Windows Process Cluster Spawned by a Parent Process

```

What these rule have in common:  
a) they are ML rules (without expecting all of them)  
b) they have a depandency to the integration "Windows"  
c) they all want to update the Windows-Integration's version dependency (Screenshot):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e5dfd44bb49e7412c09ce9140f5ac0d063af57a.png)

Can someone please point us to a solution or workaround for this?  
Elastic/Kibana version 8.15.3, on-prem, debian not containerized

---

<div class="post-metadata">

**Author:** ![Juan\_Pablo\_Djeredjia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_pablo_djeredjia/32/120185_2.png) [@Juan\_Pablo\_Djeredjia](https://discuss.elastic.co/u/Juan_Pablo_Djeredjia)\
**Post date:** [October 18, 2024, 2:57pm UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/2 "2024-10-18T14:57:46Z")

</div>

Hi @syk . Thanks for bringing this up!

I'll investigate the issue, but meanwhile, would you be able to post the full response from the rule upgrade API call?

If you open the Network tab in your browser's Dev Tools when you try to update one or more rules, you'll see the request is made to the url `POST /kbn/internal/detection_engine/prebuilt_rules/upgrade/_perform`.

You can just copy and paste the response here.

Also: did you just update your Kibana version? If you just did, can you let us know from which version to which you did?

Thanks!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 18, 2024, 3:48pm UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/3 "2024-10-18T15:48:13Z")

</div>

Quick question, do you have a paid License enabled in your cluster, platinum or enterprise?

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 21, 2024, 6:20am UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/4 "2024-10-21T06:20:59Z")

</div>

@Juan_Pablo_Djeredjia : the mentioned 18 rules are not updated because:

```auto
 "message": "Your license does not support machine learning. Please upgrade your license."

```

@leandrojmp: I guess this answers your question as well: all clusters we experience this behaviour have a basic license applied...

But why do only these 18 rules behave like that? They aren't even enabled...

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 21, 2024, 9:24am UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/5 "2024-10-21T09:24:54Z")

</div>

we upgraded from 8.15.2 to 8.15.3

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 21, 2024, 1:13pm UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/6 "2024-10-21T13:13:44Z")

</div>

> [@syk](#):
>
> I guess this answers your question as well: all clusters we experience this behaviour have a basic license applied...
> 
> But why do only these 18 rules behave like that? They aren't even enabled

Yeah, if you are using the basic license this is your issue, the ML rules require a paid license, but this is not checked while installing or updating the rules.

Also the toast informing that the update failed is also wrong, it shows the success toast (green line and check mark) and not the failure toast (red line and a x mark).

I had a similar issue and opened a github issue in August: [[Security Solution] Detection rule fails to install but does not show reason and the toast in the UI shows up as success · Issue #190753 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/190753)

You can just ignore this error, it is a bug in Kibana.

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 21, 2024, 2:05pm UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/7 "2024-10-21T14:05:49Z")

</div>

Thanks for the quick answer Leandro!

Could you please explain the topics below for clarification:

- There are currently 77 prebuilt rules tagged for "Machine Learning" - correct?  

- 18 of those will never be updated and added to other upcoming rule-updates, so the number of "Rule Updates" displayed will increase and we have to keep track of the numbers?  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2fb3cf94f65ffd5ee5531dcc704b8e5a9fbb58c8.png)

- Out of the 77 ML-rules 5 can be enabled even with only a basic license applied (see screenshot below) - is this intentional?  

- This is the wrong place to report Kibana-Bugs?

---

<div class="post-metadata">

**Author:** ![georgii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgii/32/78076_2.png) [@georgii](https://discuss.elastic.co/u/georgii)\
**Post date:** [October 22, 2024, 9:47am UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/8 "2024-10-22T09:47:05Z")

</div>

Hi @syk, thanks for the clear description of your situation. Let's please move our discussion to GitHub - this will help the right team at Elastic to track and fix the bug. Could you please open a new issue on [GitHub · Where software is built](https://github.com/elastic/kibana/issues) and drop a link to it in this thread? We'll continue from there. Thanks!

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [October 22, 2024, 1:42pm UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/9 "2024-10-22T13:42:05Z")

</div>

Link to the github topic as requested:

> <https://github.com/elastic/kibana/issues/197246>
>
> \### \*\*Describe the bug:\*\*
> Some rules (probably machine learning rules) fail to i…nstall/update when basic license is in use.
> 
> \### \*\*Kibana/Elasticsearch Stack version:\*\*
> 8.15.3
> 
> \### \*\*Server OS version:\*\*
> Debian and Ubuntu
> 
> \### \*\*Original install method (e.g. download page, yum, from source, etc.):\*\*
> Debian Package from artifacts.elastic.co
> 
> \### \*\*Functional Area (e.g. Endpoint management, timelines, resolver, etc.):\*\*
> Detection Rules
> 
> \### \*\*Steps to reproduce:\*\*
> 
> 1. Install Elasticsearch, Kibana (Debian Package)
> 2. Add Prebuilt Rules
> 3. Install all Rules (maybe the error happens here as well - could not test with a new setup)
> 4. Wait for new rules to be available (including machine learning rules)
> 5. Try to install the new rules
> 
> \### \*\*Current behavior:\*\*
> Some/all ML-rules fail to install - showing a green success-message in the bottom right of the screen "\_X rules failed to install\_" without any hint of the cause. 
> Numbers for installable rules (upgradable rules) increase over time.
> Some ML-rules can be enabled even with a basic license in use.
> 
> \### \*\*Expected behavior:\*\*
> All rules should be installable/upgradable regardless of applied license.
> 
> \### \*\*Errors in browser console:\*\*
> Request to 
> \`\[...\]internal/detection\_engine/prebuilt\_rules/install/\_perform\`
> is answered with 
> \`"message": "Your license does not support machine learning. Please upgrade your license." \`
> (same behaviour for certain conditions when requesting 
> \`\[...\]internal/detection\_engine/prebuilt\_rules/update/\_perform\`
> 
> \### \*\*Any additional context (logs, chat logs, magical formulas, etc.):\*\*
> Similar reports of this bug:
> https://github.com/elastic/kibana/issues/190753
> https://discuss.elastic.co/t/detection-rules-update-failure/369051
> Screenshot of ML-rules that can be enabled even with a basic license:
> !\[Image\](https://github.com/user-attachments/assets/402f2088-be66-4230-b858-79684a735fc4)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2024, 1:42pm UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051/10 "2024-11-19T13:42:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
