# Elastic Security Rule Exceptions vs Endpoint Exceptions

**URL:** <https://discuss.elastic.co/t/elastic-security-rule-exceptions-vs-endpoint-exceptions/355404>\
**Category:** Endpoint Security\
**Created:** [March 14, 2024, 12:34pm UTC](https://discuss.elastic.co/t/elastic-security-rule-exceptions-vs-endpoint-exceptions/355404 "2024-03-14T12:34:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![isa\_slngr](https://avatars.discourse-cdn.com/v4/letter/i/bcef8e/32.png) [@isa\_slngr](https://discuss.elastic.co/u/isa_slngr)\
**Post date:** [March 14, 2024, 12:34pm UTC](https://discuss.elastic.co/t/elastic-security-rule-exceptions-vs-endpoint-exceptions/355404/1 "2024-03-14T12:34:44Z")

</div>

Good day,

I was wondering is anyone could point me to documentation that details the difference between Rule Exceptions and Endpoint Exceptions in Elastic Security, including when to use which type of exception.

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [March 14, 2024, 1:43pm UTC](https://discuss.elastic.co/t/elastic-security-rule-exceptions-vs-endpoint-exceptions/355404/2 "2024-03-14T13:43:06Z")

</div>

I think [this documentation](https://www.elastic.co/guide/en/security/current/add-exceptions.html) is the page you're looking for.

But to answer your question more directly, rule exceptions prevent alerts from being triggered by Detection Engine rules in Kibana. Endpoint exceptions prevent Endpoint (Elastic Defend) from detecting/preventing the activity on the host being protected. In other words, rule exceptions run in Kibana and Endpoint exceptions run on the host.

Usually when adding an exception for an Endpoint alert you want to add an Endpoint exception. If you add a rule exception Endpoint will still detect/prevent the activity on the host but Kibana will hide the corresponding alert.

I hope that helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2024, 1:43pm UTC](https://discuss.elastic.co/t/elastic-security-rule-exceptions-vs-endpoint-exceptions/355404/3 "2024-04-11T13:43:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
