# How to exploit rules

**URL:** <https://discuss.elastic.co/t/how-to-exploit-rules/328174>\
**Category:** Elastic Security\
**Created:** [March 21, 2023, 2:53pm UTC](https://discuss.elastic.co/t/how-to-exploit-rules/328174 "2023-03-21T14:53:40Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![georgii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgii/32/78076_2.png) [@georgii](https://discuss.elastic.co/u/georgii)\
**Post date:** [March 23, 2023, 10:17am UTC](https://discuss.elastic.co/t/how-to-exploit-rules/328174/7 "2023-03-23T10:17:49Z")

</div>

@Iroshu It turns out there's a recent thread where another user had a similar question about reindexing alerts into a separate index.

> [@Creating Multiple Alert Documents when Alert is Triggered](https://discuss.elastic.co/t/creating-multiple-alert-documents-when-alert-is-triggered/327088):
>
> Hi all, I've got a bit of a unique issue. For the system I am developing, data records will be ingested and compared against thresholds to confirm if values are anomalous. To test out this functionality I've set up an alert that applies a range query to check if a value is acceptable or not. I've set up an index connector, so that when the alert is triggered, a document is written to a specific index. The issue I've encountered is that we require one alert document to match up to each docume…

In that thread, it was suggested that for the time being, the best workaround would be leveraging Logstash pipelines for reindexing alerts elsewhere. Related documentation:

- [Creating a Logstash pipeline | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/configuration.html)
- [Elasticsearch input plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html)

---

_[View the full topic](https://discuss.elastic.co/t/how-to-exploit-rules/328174)._
