# Failed to installed pre-packaged rules from elastic

**URL:** <https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111>\
**Category:** SIEM\
**Created:** [February 13, 2020, 2:50am UTC](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111 "2020-02-13T02:50:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wlzylal](https://avatars.discourse-cdn.com/v4/letter/w/b782af/32.png) [@wlzylal](https://discuss.elastic.co/u/wlzylal)\
**Post date:** [February 13, 2020, 2:50am UTC](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111/1 "2020-02-13T02:50:14Z")

</div>

I have just upgrade my elk to 7.6.0 and I want to test the rules in SIEM, but I just can't load prebuilt detection rules. It said that

// Your visualization has error(s)

Failed to installed pre-packaged rules from elastic

An internal server error occurred

Status Code: 500

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [February 13, 2020, 4:24am UTC](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111/2 "2020-02-13T04:24:04Z")

</div>

Hi wlzylal,

Did you upgrading an existing on premise install of the Elastic Stack? If so, do you have the Kibana log file or console you are running it on close by to peek into it to see if maybe there is more involved error message?

That 500 could be a variety of things such as but not limited to...Networking issues, disk issues, memory issues, etc... Sometimes within the Kibana logs there is a more detailed error message or a collection of other errors that proceeds this one which would help identify what is happening 🤞

Also, do you get the same 500 error message if you try and create a custom rule or just when you try to install the pre-packaged rules?

Oh and of course, welcome to the discuss forums and thanks for taking the time to post your first post!

---

<div class="post-metadata">

**Author:** ![wlzylal](https://avatars.discourse-cdn.com/v4/letter/w/b782af/32.png) [@wlzylal](https://discuss.elastic.co/u/wlzylal)\
**Post date:** [February 13, 2020, 5:52am UTC](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111/3 "2020-02-13T05:52:40Z")

</div>

Thank you for your answer!

I have solved the problem by enabling the settings of **ssl** and **api\_key** in elasticsearch.yml

like this:  
xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.keystore.path: /usr/share/elasticsearch/certs/elastic-certificates.p12  
xpack.security.http.ssl.truststore.path: /usr/share/elasticsearch/certs/elastic-certificates.p12  
xpack.security.authc.api\_key.enabled: true

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [February 13, 2020, 9:44am UTC](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111/4 "2020-02-13T09:44:07Z")

</div>

Adding the TLS configuration for the `http` endpoint of Elasticsearch did the trick. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2020, 9:44am UTC](https://discuss.elastic.co/t/failed-to-installed-pre-packaged-rules-from-elastic/219111/5 "2020-03-12T09:44:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
