# Elastic Security Threat Match rule

**URL:** https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281
**Category:** SIEM
**Created:** [September 29, 2025, 11:41am UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281 "2025-09-29T11:41:22Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)
#### Post date: [September 29, 2025, 11:41am UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281/1 "2025-09-29T11:41:22Z")

</div>

I have a couple of questions about how threat match rules work in Elasticsearch, which I feel the documentation does not cover very well.

The question is about the **Custom query** parameter, the frequency, and the additional lookback time.

What we care about is retroactive threat hunting. By default, Elasticsearch Security pre-built threat rules use a combination of 1 hour frequency and 5 minutes additional look-back time. The IoCs are filtered to only include those ingested in the last 30 days.

When you use a Custom Query `*:*` in this scenario, will it:  
a. Match the documents since the last hour and 5 minutes to the last 30 days of IoCs  
b. Match ALL of the documents specified by **Index Pattern** to the last 30 days of IoCs

---

<div class="post-metadata">

### Author: ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)
#### Post date: [September 29, 2025, 1:32pm UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281/2 "2025-09-29T13:32:28Z")

</div>

I’ve found [this](https://www.elastic.co/docs/solutions/security/detect-and-alert#support-indicator-rules), which would indicate that the default way Elastic threat rules work is they run each hour and match the indicators which appeared within the last 30 days to the last hour and 5 minutes of logs.  
Can someone with more knowledge confirm this?

---

<div class="post-metadata">

### Author: ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)
#### Post date: [September 30, 2025, 4:33pm UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281/3 "2025-09-30T16:33:09Z")

</div>

Hey @lduvnjak

Rule will query documents from source indices ( **Index patterns** ) in 1h + 5m time interval.

And rule will try to find any matches with 30 days of documents from **Indicator index patterns** field.

---

<div class="post-metadata">

### Author: ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)
#### Post date: [September 30, 2025, 6:03pm UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281/4 "2025-09-30T18:03:59Z")

</div>

Hi @vitaliidm

Thanks for the information! Are there any plans to introduce retroactive hunting further into the past?  
If I understood correctly the maximum amount currently is 24h.

---

<div class="post-metadata">

### Author: ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)
#### Post date: [October 1, 2025, 9:24am UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281/5 "2025-10-01T09:24:39Z")

</div>

Rules can be scheduled to run in past for more than 24 hours using manual scheduling:

> **[Manage detection rules | Elastic Docs](https://www.elastic.co/docs/solutions/security/detect-and-alert/manage-detection-rules#manually-run-rules)**
>
> The Rules page allows you to view and manage all prebuilt and custom detection rules. On the Rules page, you can: Sort and filter the rules list, Check...

---

<div class="post-metadata">

### Author: ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)
#### Post date: [October 1, 2025, 9:30am UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281/6 "2025-10-01T09:30:09Z")

</div>

Awesome, I didn't know that. Thanks a bunch!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 29, 2025, 9:30am UTC](https://discuss.elastic.co/t/elastic-security-threat-match-rule/382281/7 "2025-10-29T09:30:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
