# Detections with custom query

**URL:** <https://discuss.elastic.co/t/detections-with-custom-query/252628>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [October 20, 2020, 5:11am UTC](https://discuss.elastic.co/t/detections-with-custom-query/252628 "2020-10-20T05:11:34Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [October 22, 2020, 9:53am UTC](https://discuss.elastic.co/t/detections-with-custom-query/252628/3 "2020-10-22T09:53:22Z")

</div>

Hi,  
I 'm experiencing the same problem that @Anirudhan.  
I've create a custom (very simple rule) on a custom index containing Fortinet Logs and it is not generating signals (although many events exists) . (See below)

As far I understand this is a diferent situation than in [Threshold rules not triggering on selfmade index](https://discuss.elastic.co/t/threshold-rules-not-triggering-on-selfmade-index/251029/14) , in fact threshold rules **are** working but custom querys not

**Non-working Detection rule**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6db9976bd4f26c6496fff76631b168e14cef79f.png)

When a create a threshold rules with the same query, events are generated

**Working Threshold rule**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0da12c4867d61332c6ed83309e99ff01f9bd2967.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/255afceff00df48a8ceee496afccb903e8818de0.png)

**[Index Mapping](https://pastebin.pl/view/7a025429)**

Thank you  
Regads  
Anna

---

_[View the full topic](https://discuss.elastic.co/t/detections-with-custom-query/252628)._
