# Detection rules

**URL:** <https://discuss.elastic.co/t/detection-rules/257785>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [December 6, 2020, 8:21pm UTC](https://discuss.elastic.co/t/detection-rules/257785 "2020-12-06T20:21:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cosmin\_Ciobanu1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cosmin_ciobanu1/32/78785_2.png) [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Post date:** [December 6, 2020, 8:21pm UTC](https://discuss.elastic.co/t/detection-rules/257785/1 "2020-12-06T20:21:41Z")

</div>

How can I check when I make a detection rule if another rule has been activated? That is, if I want to make a rule that verifies an incident I would like to check if another rule that is strictly related to IDS has already been activated.

Thank you very much!

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [December 10, 2020, 3:10pm UTC](https://discuss.elastic.co/t/detection-rules/257785/2 "2020-12-10T15:10:14Z")

</div>

you can create rules that point at the signals index .siem-signals-default-\*  
thing is that query would only be using that index. It is possible to create multiple alerts based on various indexs then create a rule the runs against the .siem-signals-default-\*

name the rules with a prefix then use threshold with .siem-signals-default-\* to alert of x events with that prefix alert in x minutes.

---

<div class="post-metadata">

**Author:** ![Cosmin\_Ciobanu1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cosmin_ciobanu1/32/78785_2.png) [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Post date:** [December 10, 2020, 7:39pm UTC](https://discuss.elastic.co/t/detection-rules/257785/3 "2020-12-10T19:39:55Z")

</div>

Thank you !

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [December 14, 2020, 4:08pm UTC](https://discuss.elastic.co/t/detection-rules/257785/4 "2020-12-14T16:08:00Z")

</div>

fwiw, you don't have to do `.siem-signals-default-*`, you should only have to use `.siem-signals-default` when you're in the default space as that is an alias which will access all the ILM indexes correctly. If you are in a different space it would be `.siem-signals-${space-id}` where ${space-id} is the space id you have created.

Please let me know if you are finding this to be a problem and are having to resort to using `.siem-signals-default-*` with a glob pattern. We made the siem signals detection work with ILM and aliases.

If you are reaching across spaces then it would be `.siem-signals*` or `siem-signals-${space-id1},siem-signals-${space-id2}` when setting up Kibana indexes with regards to dashboards. Then just setup your permissions per space according to your use cases.

With all of that said you could still use a glob like mentioned above, it shouldn't hurt anything major unless you have specific use cases and changes to the existing ILM policies and how you're aging out closed signals.

Ref on ILM:

> **[ILM: Manage the index lifecycle | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2021, 4:08pm UTC](https://discuss.elastic.co/t/detection-rules/257785/5 "2021-01-11T16:08:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
