# Filtering Rules according to "Last response" Field

**URL:** <https://discuss.elastic.co/t/filtering-rules-according-to-last-response-field/275743>\
**Category:** Elastic Security\
**Created:** [June 13, 2021, 12:35am UTC](https://discuss.elastic.co/t/filtering-rules-according-to-last-response-field/275743 "2021-06-13T00:35:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [June 13, 2021, 12:35am UTC](https://discuss.elastic.co/t/filtering-rules-according-to-last-response-field/275743/1 "2021-06-13T00:35:44Z")

</div>

Hi there,

As I understand, there are 3 kinds of `Last response` for rules - Succeeded, Warning, and Failure.

I would like to filter rules according to just these 3 statuses. It appears that there is currently no way of doing so, based on what I have seen at both the `Rules` and `Rule Monitoring` page (both of which contain the same `Last response` field). The Up/Down arrow button does not appear when I hover my cursor over the column name (unlike the 3 columns which have this feature - `Rule`, `Last updated` and `Activated`).

The reason why I would like to do so, is because there are some rules which rely on some Beats which I am not using. These rules happen to have the `Warning` status. Thus, I would like to quickly filter for these rules with `Warning` status, then deactivate them in one fell swoop.

In summary, I am looking to:

- Either: Filtering rules according to the `Last response` field
- Or: A way to filter rules based on its data sources

Having both would be awesome in the long-run I suppose, but my immediate need is for the latter.

(P.S. My apologies in advance if this is due to a knowledge gap on my part, rather than an unimplemented feature.)

Thank you for your time!

---

<div class="post-metadata">

**Author:** ![Michael\_Olorunnisola](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_olorunnisola/32/88980_2.png) [@Michael\_Olorunnisola](https://discuss.elastic.co/u/Michael_Olorunnisola)\
**Post date:** [June 15, 2021, 3:38pm UTC](https://discuss.elastic.co/t/filtering-rules-according-to-last-response-field/275743/2 "2021-06-15T15:38:31Z")

</div>

Hi @inf - You are correct, there is no way currently to actually sort the `Last Response` field. Would the rules you're looking to filter out have specific `tags` you can use to filter them?

---

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [June 16, 2021, 12:37pm UTC](https://discuss.elastic.co/t/filtering-rules-according-to-last-response-field/275743/3 "2021-06-16T12:37:43Z")

</div>

Hello! Thank you for your reply.

Unfortunately, these rules do not have common `tags`.

Nonetheless, I greatly appreciate your time in replying! Have a great week ahead. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2021, 12:38pm UTC](https://discuss.elastic.co/t/filtering-rules-according-to-last-response-field/275743/4 "2021-07-14T12:38:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
