# EQL Detection Rule issues

**URL:** <https://discuss.elastic.co/t/eql-detection-rule-issues/376641>\
**Category:** SIEM\
**Created:** [April 1, 2025, 12:59pm UTC](https://discuss.elastic.co/t/eql-detection-rule-issues/376641 "2025-04-01T12:59:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kiwisaki](https://avatars.discourse-cdn.com/v4/letter/k/dfb087/32.png) [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Post date:** [April 1, 2025, 12:59pm UTC](https://discuss.elastic.co/t/eql-detection-rule-issues/376641/1 "2025-04-01T12:59:05Z")

</div>

Hi, So i'm having some issues with my EQL detection rules. One of the use cases im running with is a possible BF attempt on a windows host.

I currently have the following EQL in place which returns results fine in timeline...

sequence by user.name with maxspan = 2m  
[any where event.code == "4625"]  
[any where event.code == "4625"]  
[any where event.code == "4625"]  
[any where event.code == "4624"]

However, when i use this same query in a security detection rule, it never triggers despite seeing logs in Discover that match at the time and also verifying the query within timeline.

Am i missing something ??

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [April 4, 2025, 5:21pm UTC](https://discuss.elastic.co/t/eql-detection-rule-issues/376641/2 "2025-04-04T17:21:19Z")

</div>

Hey @Kiwisaki,

There's a [recent post](https://discuss.elastic.co/t/look-back-time-and-maxspan-in-eql/358874) discussing how rule scheduling works with EQL's `maxspan` key; you may find your answer there. If your query works elsewhere, then it's possible that the rule cannot "see" the full sequence of events due to how it's configured. **If you're able to share the rule configuration** , we could make that determination.

Another common issue that could be in play here is [ingestion delay](https://www.elastic.co/guide/en/security/current/alerts-ui-monitor.html#troubleshoot-ingestion-pipeline-delay). If e.g. your events are taking 4 minutes to become searchable in elasticsearch, then most of the events won't be available when your rule looks at the last 5 minutes of data (they would later be available in Discover, though).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2025, 5:21pm UTC](https://discuss.elastic.co/t/eql-detection-rule-issues/376641/3 "2025-05-02T17:21:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
