# Elastic detection rules fail

**URL:** <https://discuss.elastic.co/t/elastic-detection-rules-fail/334547>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [May 29, 2023, 4:25am UTC](https://discuss.elastic.co/t/elastic-detection-rules-fail/334547 "2023-05-29T04:25:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [May 29, 2023, 4:25am UTC](https://discuss.elastic.co/t/elastic-detection-rules-fail/334547/1 "2023-05-29T04:25:37Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75181c470d0ac814ff7536b445e9a814181c70af.png)

```auto
Rule failure at May 29, 2023 @ 12:09:44.438
Bulk Indexing of signals failed: ResponseError: search_phase_execution_exception

Caused by:

illegal_argument_exception: Can't sort on field [event.ingested]; the field has incompatible sort types: [STRING] and [LONG] across shards!

```

Elasticity detection rules display a large number of fail errors. What is the reason? What is the solution? Thanks.

---

<div class="post-metadata">

**Author:** ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)\
**Post date:** [June 2, 2023, 3:46pm UTC](https://discuss.elastic.co/t/elastic-detection-rules-fail/334547/2 "2023-06-02T15:46:43Z")

</div>

Hi @xqaiviwjxzw

Can you please tell which version of Elasticsearch/Kibana are you using?  
Looking at error, it seems like your rule queries indices that have different mapping for "event.ingested". According to ECS schema event.ingested should be of date format: [Event Fields | Elastic Common Schema (ECS) Reference [8.8] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-event.html#field-event-ingested)  
Can you please check mapping for queried indices to understand whether my hypothesis is correct?  
If it so, there are few ways to proceed

1. Ensure all indices that rule queries, have the same mapping for event.ingested. Can be achieved by editing rule, removing indices that have different mapping. Another rule can be added that have the removed indices from the first one
2. Reindexing the data to ensure it has the same format, preferably ECS compliant date across all indices

Thanks, Vitalii

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2023, 3:46pm UTC](https://discuss.elastic.co/t/elastic-detection-rules-fail/334547/3 "2023-06-30T15:46:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
