# Error after creating Detection rules in Elastic Security; Not getting alerts

**URL:** https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908
**Category:** SIEM
**Created:** [April 15, 2026, 10:23pm UTC](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908 "2026-04-15T22:23:15Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![wicklanm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wicklanm/32/140035_2.png) [@wicklanm](https://discuss.elastic.co/u/wicklanm)
#### Post date: [April 15, 2026, 10:23pm UTC](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908/1 "2026-04-15T22:23:15Z")

</div>

Hey everyone,

After I added Security Detection Rules in my Elastic Search, I get the following error below. what does this mean and what can I do to fix it? I am not getting any alerts from this. This is for my Windows Server virtual machine hosted on VULTR, where I have Elastic search installed on a separate server, and they are connected. There is an active Elastic Agent for the Windows Server. I have tried restarting the Windows Server machine, but I am still getting this error. Any ideas?

Error: Forbidden  
at Fetch.fetchResponse

 ![15_detectionruleerror](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f765d46bd9e0e4a92bac600217d8f0bc3e8e6d68.png)

#detection-rules

---

<div class="post-metadata">

### Author: ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)
#### Post date: [April 16, 2026, 2:53am UTC](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908/2 "2026-04-16T02:53:18Z")

</div>

Hi @wicklanm , it looks like you're experiencing [this bug](https://github.com/elastic/kibana/issues/246011) present in 9.3.0. As stated in the issue, it should be fixed in 9.3.4 and 9.4.0. Let me know if you have further questions!

---

<div class="post-metadata">

### Author: ![wicklanm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wicklanm/32/140035_2.png) [@wicklanm](https://discuss.elastic.co/u/wicklanm)
#### Post date: [April 16, 2026, 4:07am UTC](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908/3 "2026-04-16T04:07:33Z")

</div>

Hey everyone,

After I added Security Detection Rules in my Elastic Search, I get the following error below. what does this mean and what can I do to fix it? I am not getting any alerts from this. This is for my Windows Server virtual machine hosted on VULTR, where I have Elastic search installed on a separate server, and they are connected. There is an active Elastic Agent for the Windows Server. I have tried restarting the Windows Server machine, but I am still getting this error. Any ideas?

Error: Forbidden  
at Fetch.fetchResponse

 ![15_detectionruleerror](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f765d46bd9e0e4a92bac600217d8f0bc3e8e6d68.png)

#detection-rules Ok Thank You! Would this be a rolling update stack that I would have to follow? This is a self-managed cluster installed on a Linux virtual server.

> **[Upgrade the Elastic Stack on a self-managed cluster | Elastic Docs](https://www.elastic.co/docs/deploy-manage/upgrade/deployment-or-cluster/self-managed)**
>
> If you've installed the Elastic Stack on your own self-managed infrastructure, once you're prepared to upgrade, you'll need to upgrade each of your Elastic...

---

<div class="post-metadata">

### Author: ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)
#### Post date: [April 16, 2026, 7:05pm UTC](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908/4 "2026-04-16T19:05:02Z")

</div>

@wicklanm those docs you shared should allow you to upgrade your stack once the bugfix is released, yes. I assume you're on 9.3.x; I'm not currently aware of any specific upgrade callouts from 9.3.x to e.g. 9.4.0, but please check release notes when those versions are available for any such information.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 14, 2026, 7:05pm UTC](https://discuss.elastic.co/t/error-after-creating-detection-rules-in-elastic-security-not-getting-alerts/385908/5 "2026-05-14T19:05:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
