# Detection-rules

**URL:** <https://discuss.elastic.co/t/detection-rules/269219>\
**Category:** Elastic Security\
**Created:** [April 5, 2021, 9:40am UTC](https://discuss.elastic.co/t/detection-rules/269219 "2021-04-05T09:40:04Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 5, 2021, 9:40am UTC](https://discuss.elastic.co/t/detection-rules/269219/1 "2021-04-05T09:40:04Z")

</div>

Hi,  
i hope this message finds you well , so how to add the project elastic/detection-rules to my elk stack  
regards and thanks

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 5, 2021, 2:23pm UTC](https://discuss.elastic.co/t/detection-rules/269219/2 "2021-04-05T14:23:22Z")

</div>

Hi

If you use v 7.12:  
What you need to do is clicking into detections. (Kibana-\>Elastic Security-\>Detections) . Click on Manage rules.  
There you find a button to load Pre build Elastic rules.

You can also download 3rd party detection rules like the ones from Sigma:

> **[Solutions | Elastic Security examples | Download now at elastic content share](https://elastic-content-share.eu/downloads/category/solutions/elastic-security/)**
>
> Download pre build content for Solutions | Elastic Security

---

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 6, 2021, 3:40pm UTC](https://discuss.elastic.co/t/detection-rules/269219/3 "2021-04-06T15:40:08Z")

</div>

thanks for your reply  
could you tell me if there is a method to integrate this project ([GitHub - elastic/detection-rules: Rules for Elastic Security's detection engine](https://github.com/elastic/detection-rules)) into my elk stack  
regards

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 6, 2021, 4:35pm UTC](https://discuss.elastic.co/t/detection-rules/269219/4 "2021-04-06T16:35:28Z")

</div>

Thats what happening when you click on load pre build elastic rules in Kibana as described above

---

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 7, 2021, 9:52am UTC](https://discuss.elastic.co/t/detection-rules/269219/5 "2021-04-07T09:52:23Z")

</div>

Thanks for your reply  
does this features need a paid Xpack or free X-pack is enough ?  
regards

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 7, 2021, 10:42am UTC](https://discuss.elastic.co/t/detection-rules/269219/6 "2021-04-07T10:42:17Z")

</div>

Its available in the free version. However if you would like to also leverage Machine Learning based rules I recommend to test the Platinum version.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/3/3344f6d7050715acf3a6c030af7599ef974c3805.png)

---

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 7, 2021, 10:45am UTC](https://discuss.elastic.co/t/detection-rules/269219/7 "2021-04-07T10:45:53Z")

</div>

So how much Platinum,Entreprise version cost

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 7, 2021, 2:48pm UTC](https://discuss.elastic.co/t/detection-rules/269219/8 "2021-04-07T14:48:11Z")

</div>

You need to fill in the contact form the get those information based on your region you are living

> **[Sie haben Fragen? Kontaktieren Sie Elastic](https://www.elastic.co/de/contact)**
>
> Sie haben eine Frage? Sie benötigen Hilfe? Sie möchten Elastic kontaktieren? Unsere Mitarbeiter in aller Welt sind gern bereit, Ihre Fragen zu beantworten und Ihnen die Informationen zu geben, die Sie benötigen.

---

<div class="post-metadata">

**Author:** ![dddddddddddddddd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dddddddddddddddd/32/86746_2.png) [@dddddddddddddddd](https://discuss.elastic.co/u/dddddddddddddddd)\
**Post date:** [April 7, 2021, 4:26pm UTC](https://discuss.elastic.co/t/detection-rules/269219/9 "2021-04-07T16:26:26Z")

</div>

thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2021, 4:27pm UTC](https://discuss.elastic.co/t/detection-rules/269219/10 "2021-05-05T16:27:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
