# EQL Detection Rule issues

**URL:** <https://discuss.elastic.co/t/eql-detection-rule-issues/376641>\
**Category:** SIEM\
**Created:** [April 1, 2025, 12:59pm UTC](https://discuss.elastic.co/t/eql-detection-rule-issues/376641 "2025-04-01T12:59:05Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [April 4, 2025, 5:21pm UTC](https://discuss.elastic.co/t/eql-detection-rule-issues/376641/2 "2025-04-04T17:21:19Z")

</div>

Hey @Kiwisaki,

There's a [recent post](https://discuss.elastic.co/t/look-back-time-and-maxspan-in-eql/358874) discussing how rule scheduling works with EQL's `maxspan` key; you may find your answer there. If your query works elsewhere, then it's possible that the rule cannot "see" the full sequence of events due to how it's configured. **If you're able to share the rule configuration** , we could make that determination.

Another common issue that could be in play here is [ingestion delay](https://www.elastic.co/guide/en/security/current/alerts-ui-monitor.html#troubleshoot-ingestion-pipeline-delay). If e.g. your events are taking 4 minutes to become searchable in elasticsearch, then most of the events won't be available when your rule looks at the last 5 minutes of data (they would later be available in Discover, though).

---

_[View the full topic](https://discuss.elastic.co/t/eql-detection-rule-issues/376641)._
