# Elastic Security Detection Rule Management - Update of Duplicates

**URL:** <https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, detection-rules\
**Created:** [July 4, 2023, 10:28am UTC](https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550 "2023-07-04T10:28:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hanna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hanna/32/109117_2.png) [@hanna](https://discuss.elastic.co/u/hanna)\
**Post date:** [July 4, 2023, 10:28am UTC](https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550/1 "2023-07-04T10:28:57Z")

</div>

Hi everyone,

does anyone have experience with managing prebuilt detection rules with your own index-patterns and exceptions?

Right now I load the prebuilt rules into kibana and then duplicate them in order to add my own index-patterns. (I am using mostly custom logstash Pipelines to integrate my log sources, so none of them are in the preconfigured index-patterns)  
However this means I have no way of updating those duplicates, whenever theres a new version of the prebuilt rules available.

Is there a way to update those rule duplicates but keep my custom index-patterns and exception lists? Or even better - is there a proven method of detection rule management that I don't know of?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2023, 10:29am UTC](https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550/2 "2023-08-01T10:29:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
