Please specify which area and pages of Elastic Security are you using when enabling rules.
If you're using the Detections API directly, please clarify which endpoint with what parameters are you calling.
Please attach relevant screenshots.
Please share an example rule with which we could reproduce the issue. Make sure to obfuscate sensitive rule parameters (e.g., any mentions of host names and IPs in the rule query) and test that it's reproducible with the obfuscated rule.
When the issue is created, you can tag @banderror (me) in the comments and we will triage it or redirect as needed.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.