# FIlter in the rule interface

**URL:** <https://discuss.elastic.co/t/filter-in-the-rule-interface/382408>\
**Category:** Elastic Security\
**Created:** [October 3, 2025, 7:32pm UTC](https://discuss.elastic.co/t/filter-in-the-rule-interface/382408 "2025-10-03T19:32:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 3, 2025, 7:32pm UTC](https://discuss.elastic.co/t/filter-in-the-rule-interface/382408/1 "2025-10-03T19:32:28Z")

</div>

Hello,

So is there a way to search or filter on severity of the rule?

Grtz

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f93feb04f4b6f3f0bb7349e8bfc7de41bda23517.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 3, 2025, 7:41pm UTC](https://discuss.elastic.co/t/filter-in-the-rule-interface/382408/2 "2025-10-03T19:41:57Z")

</div>

> [@willemdh](#):
>
> So is there a way to search or filter on severity of the rule?

Unfortunately, no.

One alternative would be to create a custom tag on your rules, something like `Severity: high`, then you would be able to filter by this tag (one at time, as the filter is an AND, not an OR).

The rule management lacks a lot of management features, on my company we created a custom automation using he rules api to export the rules and reingest this on a custom index where we can build dashboards as we want.

I also opened some issues in Github with some suggestions a couple of years ago.

Like this one: [[Security Solution] Create a Rule Overview page with built-in visualizations to improve Rule Management · Issue #190756 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/190756) and this one [[Security Solution] Allow an option to filter the Detection Rules if the integration needed is installed or not. · Issue #167333 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/167333)

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 4, 2025, 11:49am UTC](https://discuss.elastic.co/t/filter-in-the-rule-interface/382408/3 "2025-10-04T11:49:42Z")

</div>

I think it would be really helpful if the Rules interface had better built-in search and filtering options.

I’ve also upvoted your GitHub issues ([#190756](https://github.com/elastic/kibana/issues/190756), [#167333](https://github.com/elastic/kibana/issues/167333)) because this would really help in day-to-day operations, especially when reviewing or tuning rules in larger environments.

Thanks @leandrojmp !
