# Detections with custom query

**URL:** <https://discuss.elastic.co/t/detections-with-custom-query/252628>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [October 20, 2020, 5:11am UTC](https://discuss.elastic.co/t/detections-with-custom-query/252628 "2020-10-20T05:11:34Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [October 21, 2020, 5:04pm UTC](https://discuss.elastic.co/t/detections-with-custom-query/252628/2 "2020-10-21T17:04:12Z")

</div>

There's an in-depth explanation of parts fo the threshold rules with regards to fields that are aggregatable vs non-aggretable here that should help you out for trouble shooting issues:

> [@Threshold rules not triggering on selfmade index](https://discuss.elastic.co/t/threshold-rules-not-triggering-on-selfmade-index/251029/15):
>
> Well the good news is we just logged an issue where we are no longer going to allow users to use thresholds on "non-aggregatable" fields so we can give a better UI/UX experience: So, thank you for the forum posts and looking at things. In the meantime, before that bug fix goes across I am going to explain a bit about keyword/text fields, aggregatables and mapping conflicts for you and anyone else currently running into this so you know how/why this is the way it is. If you look at how the…

---

_[View the full topic](https://discuss.elastic.co/t/detections-with-custom-query/252628)._
