Event correlation query not generating detection alerts

This is prebuilt detection rule with event correlation. If I am executing query manually then it showing the correct hits.

But this is not generating any alerts.

Same story with every rule with event correlation. Rules with simple query are working as expected.

Can someone help here? Updates are here- Event correlation query not generating detection alerts · Issue #1151 · elastic/detection-rules · GitHub

@jamesspi Could you help as you also worked on the github issue?

Hey @Felix_Roessel , this is resolved now - the sysmon module does not populate event.ingested, causing the detection rule to miss, since it's specified as an override field. The solution is to remove the override.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.