# How does the look-back time of detection rules work?

**URL:** https://discuss.elastic.co/t/how-does-the-look-back-time-of-detection-rules-work/374118
**Category:** Elastic Security
**Tags:** detection-rules
**Created:** [February 5, 2025, 10:28am UTC](https://discuss.elastic.co/t/how-does-the-look-back-time-of-detection-rules-work/374118 "2025-02-05T10:28:04Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![pok\_lehbim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pok_lehbim/32/140579_2.png) [@pok\_lehbim](https://discuss.elastic.co/u/pok_lehbim)
#### Post date: [February 5, 2025, 10:28am UTC](https://discuss.elastic.co/t/how-does-the-look-back-time-of-detection-rules-work/374118/1 "2025-02-05T10:28:05Z")

</div>

What time period do rules look over when they are ran (automatically)? Is that defined by the look-back time we set?

If that's the case, I've come across some odd behavior from a custom threshold rule (grouped by 3 occurrences on the same `host.name`) where I've set the look-back time to 1 second (for testing purposes). Yet when I run a preview, these events trigger an alert despite spanning a 4 second period:

```auto
Feb 5, 2025 @ 10:16:10.306
Feb 5, 2025 @ 10:16:08.209
Feb 5, 2025 @ 10:16:06.091

```

I must be misunderstanding the time period that rules look over and how it is defined, could someone clarify this issue?

---

<div class="post-metadata">

### Author: ![georgii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgii/32/78076_2.png) [@georgii](https://discuss.elastic.co/u/georgii)
#### Post date: [February 5, 2025, 12:48pm UTC](https://discuss.elastic.co/t/how-does-the-look-back-time-of-detection-rules-work/374118/2 "2025-02-05T12:48:56Z")

</div>

Hi @pok_lehbim, when a rule runs it queries the time period between `now - (interval + look-back)` and `now`.

We can refer to the [docs](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rule-schedule) where it's explained in different words:

> For example, if you set a rule to run every 5 minutes with an additional look-back time of 1 minute, the rule runs every 5 minutes but analyzes the documents added to indices during the last 6 minutes.

> It is recommended to set the `Additional look-back time` to at least 1 minute. This ensures there are no missing alerts when a rule does not run exactly at its scheduled time.

Hope this helps!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 5, 2025, 12:48pm UTC](https://discuss.elastic.co/t/how-does-the-look-back-time-of-detection-rules-work/374118/3 "2025-03-05T12:48:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
