# Elastic rule throwing error when checking for preview

**URL:** <https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 22, 2022, 4:23pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643 "2022-08-22T16:23:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![siemdude](https://avatars.discourse-cdn.com/v4/letter/s/e495f1/32.png) [@siemdude](https://discuss.elastic.co/u/siemdude)\
**Post date:** [August 22, 2022, 4:23pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/1 "2022-08-22T16:23:45Z")

</div>

I have built a rule in Elastic following my search keywords in Discover. However the rule throws error while checking for preview and never fires. I think logic is solid, indexing is solid as well. But not sure what is causing this. Following is the error I see. I need to get to the root cause of this and need help to troubleshoot this.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/793fb85331edf7346be16fe01eafa9029f5b25be.png)

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [August 22, 2022, 6:14pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/2 "2022-08-22T18:14:32Z")

</div>

@siemdude Can you provide the rule definition for your rule? Are you saying that the rule runs successfully but only the preview functionality throws this error?

---

<div class="post-metadata">

**Author:** ![siemdude](https://avatars.discourse-cdn.com/v4/letter/s/e495f1/32.png) [@siemdude](https://discuss.elastic.co/u/siemdude)\
**Post date:** [August 22, 2022, 7:28pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/3 "2022-08-22T19:28:22Z")

</div>

No. I meant that it doesn't run. And while trying to understand the issue, I found this error in preview. Following is the rule definition.

**Index patterns:** mssp-\* dfir-\*  
**Custom query:** eventDesc :"_New Suspicious threat detected_" or eventDesc :"_New active threat_"  
**Rule type:** Query  
**Timeline template:** Comprehensive Process Timeline

> [@ying.mao](#):
>
> @siemdude Can you provide the rule definition for your rule? Are you saying that the rule runs successfully but only the preview functionality throws this error?

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [August 22, 2022, 8:05pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/4 "2022-08-22T20:05:47Z")

</div>

Thanks @siemdude. Are the mssp-\* and dfir-\* indices ECS compliant?

---

<div class="post-metadata">

**Author:** ![siemdude](https://avatars.discourse-cdn.com/v4/letter/s/e495f1/32.png) [@siemdude](https://discuss.elastic.co/u/siemdude)\
**Post date:** [August 22, 2022, 8:10pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/6 "2022-08-22T20:10:47Z")

</div>

I am not sure if this is ecs compliant. We're are receiving logs from a logstash.

Source -\> logstash-\>elasticsearch.

I want to add that, I've found a field 'Host' coming as a static value across multiple records just like the warning in Preview says. I have confirmed this by checking the actual records.

---

<div class="post-metadata">

**Author:** ![siemdude](https://avatars.discourse-cdn.com/v4/letter/s/e495f1/32.png) [@siemdude](https://discuss.elastic.co/u/siemdude)\
**Post date:** [August 23, 2022, 4:28pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/7 "2022-08-23T16:28:52Z")

</div>

I think these are not ECS compliant. Any suggestions?

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [August 23, 2022, 4:45pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/8 "2022-08-23T16:45:29Z")

</div>

I believe security detection rules must run on ECS compliant data. If your data is not ECS compliant, you might try an [ES Query rule](https://www.elastic.co/guide/en/kibana/master/rule-type-es-query.html) to define a custom query.

---

<div class="post-metadata">

**Author:** ![siemdude](https://avatars.discourse-cdn.com/v4/letter/s/e495f1/32.png) [@siemdude](https://discuss.elastic.co/u/siemdude)\
**Post date:** [August 25, 2022, 9:02pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/9 "2022-08-25T21:02:35Z")

</div>

I am in version 8.3. I don't see an option for ES query like previous versions. Which specific rule type I should select for ES query?

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [August 29, 2022, 1:25pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/10 "2022-08-29T13:25:26Z")

</div>

The ES query rule is not a security rule. You can find it in Stack Management \> Rules and Connectors if you create a rule from that page.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2022, 1:26pm UTC](https://discuss.elastic.co/t/elastic-rule-throwing-error-when-checking-for-preview/312643/11 "2022-09-26T13:26:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
