# Elastic Security Rule Error "failed to parse field \[\_index\]"

**URL:** <https://discuss.elastic.co/t/elastic-security-rule-error-failed-to-parse-field-index/371684>\
**Category:** Kibana\
**Created:** [December 9, 2024, 8:43am UTC](https://discuss.elastic.co/t/elastic-security-rule-error-failed-to-parse-field-index/371684 "2024-12-09T08:43:38Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![wangsubo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wangsubo/32/133865_2.png) [@wangsubo](https://discuss.elastic.co/u/wangsubo)\
**Post date:** [December 9, 2024, 8:43am UTC](https://discuss.elastic.co/t/elastic-security-rule-error-failed-to-parse-field-index/371684/1 "2024-12-09T08:43:38Z")

</div>

I tried to set up a rule called “Excessive Firewall or ACL Denies from Single Source IP,” but it failed with the following error:  
`failed to parse field [_index] of type [_index] in document with id ...`

Here are the details of the rule configuration:

1. **Index Patterns:** logs-\* and
2. **Custom Query:** `(event.action : "deny" or event.action : "block" or event.action : "drop") and @timestamp >= now-5m`
3. **Group By:** source.ip and \_index
4. **Threshold:** \>= 600

The goal of this rule is to detect cases where a single source IP is excessively denied within 5 minutes, as this could indicate brute force or reconnaissance activities.

However, I need to use `_index` as a Group By condition, so removing it is not an option. Has anyone encountered a similar issue or know how to resolve this error? Could it be related to index structure or some specific configuration?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/2/722cd9aed94f954ee8d608806c2ef598e545ef81.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/6/b63011f4eb0efb6373e91ec8dd3e27a745ec91a4.png)
