# How to handle host specific (maintenance) exceptions for SIEM security rules?

**URL:** https://discuss.elastic.co/t/how-to-handle-host-specific-maintenance-exceptions-for-siem-security-rules/376584
**Category:** Elastic Security
**Created:** [March 31, 2025, 1:17pm UTC](https://discuss.elastic.co/t/how-to-handle-host-specific-maintenance-exceptions-for-siem-security-rules/376584 "2025-03-31T13:17:36Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![falk](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@falk](https://discuss.elastic.co/u/falk)
#### Post date: [March 31, 2025, 1:17pm UTC](https://discuss.elastic.co/t/how-to-handle-host-specific-maintenance-exceptions-for-siem-security-rules/376584/1 "2025-03-31T13:17:36Z")

</div>

Hello,

is there a way/what is the preferred way to exclude Elastic Agents/hosts under maintenance (the client system themselves) from security alerts?  
Basically: do an exception to one or more hosts under maintenance.

Kibana has a technical preview feature called "Maintenance windows".  
I then used "Filters" / "Filter alerts".  
Then "Select the categories this should affect" -\> "Security rules"

For example, a normal EQL query like `host.name: "parser-001.env1"` or `host.name: parser-00*.env1` doesn't work here for me.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/b/ebc81868ab5b9466fec9424a9a0bccc2b7b44194.png)

Furthermore, even filtering out rules via their rule names hasn't worked.  
`kibana.alert.rule.name: "Connection to Internal Network via Telnet" or kibana.alert.rule.name: "Connection to External Network via Telnet"`.

The host names and rule names are correct and even shown as suggested values.

Using the maintenance windows without a filter works perfectly, but this is too much filtering for just updating some hosts.

My current version of the Elastic cluster is still 8.16.1. But there seem to be no relevant changelogs on this topic.

Another way may be a "rule exception". However, it would be quite tedious to add and later remove 10 hostnames from every of the "top 10" spammy rules. Rare alerts could still be triggered as well. So excluding the hosts from a central point instead makes sense.

Some rules produce a lot of false positives (when a client system is updated), but should not be deactivated entirely or for the whole environment.

The documentation has no details about this topic.

> **[Maintenance windows | Kibana Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/kibana/current/maintenance-windows.html)**

These git issues seem relevant, however it is not my exact use case.

> <https://github.com/elastic/kibana/issues/188304>
>
> \## Steps to reproduce
> 1. Modify the ES Query rule to force an array of values o…n \`host.name\` (shortcut for copying values)
> 
> \`\`\`
> diff --git a/x-pack/plugins/stack\_alerts/server/rule\_types/es\_query/executor.ts b/x-pack/plugins/stack\_alerts/server/rule\_types/es\_query/executor.ts
> index 5e23bf9498e..974fb733bfa 100644
> \--- a/x-pack/plugins/stack\_alerts/server/rule\_types/es\_query/executor.ts
> +++ b/x-pack/plugins/stack\_alerts/server/rule\_types/es\_query/executor.ts
> @@ -166,6 +166,7 @@ export async function executor(core: CoreSetup, options: ExecutorOptions\<EsQuery
> state: { latestTimestamp, dateStart, dateEnd },
> context: actionContext,
> payload: {
> + 'host.name': \['foo', 'bar'\],
> \[ALERT\_URL\]: actionContext.link,
> \[ALERT\_REASON\]: actionContext.message,
> \[ALERT\_TITLE\]: actionContext.title,
> \`\`\`
> 
> 2. Startup a fresh Kibana instance
> 3. Create a maintenance window for stack rules with the following KQL filter: \`host.name: "foo"\`
> 4. Create an ES Query rule that fires an alert and has a server log action
> 5. Wait for the rule to run, detect and alert and attach the maintenance window to it
> 6. Notice no actions fired while \`bar\` a also host of this alert not part of the maintenance window
> 
> \## Expected result
> Maintenance window to not apply given \`bar\` is a host that isn't part of the maintenance window and the system suppressed a notification that should have sent out.

> <https://github.com/elastic/kibana/issues/187812>
>
> \*\*Kibana version:\*\* 8.14.2
> 
> \*\*Elasticsearch version:\*\* 8.14.2
> 
> \*\*Describe th…e bug:\*\*
> 
> The maintenance window for alerting in Stack Management allows to set filters and only apply the maintenance window to certain criteria. 
> If one were to specify the \`kibana.alert.group.value\` as a possible way to filter a specific \`host.name\` in a rule that sets the hostname as a "group alerts by" filter, it works if one were to specify a single value. But if one were to specify multiple values, then only one value will apply to the filters and the remaining values will fail. 
> 
> For example, this works:
> \<img width="1271" alt="Screenshot 2024-07-08 at 7 22 59 PM" src="https://github.com/elastic/kibana/assets/62263912/3b59729c-20c9-4f4b-a241-96debeff28d9"\>
> 
> But this doesn't and only one value gets filtered (in this case host2):
> 
> \<img width="1310" alt="Screenshot 2024-07-08 at 7 23 53 PM" src="https://github.com/elastic/kibana/assets/62263912/d62a9a1d-13d0-4d3f-a458-6312fa010142"\>
> 
> 
> \*\*Steps to reproduce:\*\*
> 
> 1. Configure a custom threshold rule. Specifying "Group Alerts by" to \`host.name\`.
> 2. Enable a maintenance window and set a filter for observability to \`kibana.alert.group.value\` is one of \`host1\` or \`host2\`
> 3. Cause a condition that triggers the alert. 
> 4. Observe that \`host2\` triggers and alert and \`host1\` doesn't.
> 
> \*\*Expected behavior:\*\*
> 
> Both \`host2\` and \`host1\` shouldn't trigger alerts.

Thank you.

---

<div class="post-metadata">

### Author: ![falk](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@falk](https://discuss.elastic.co/u/falk)
#### Post date: [April 7, 2025, 10:18am UTC](https://discuss.elastic.co/t/how-to-handle-host-specific-maintenance-exceptions-for-siem-security-rules/376584/2 "2025-04-07T10:18:27Z")

</div>

Okay, I think it is solved. There is the slightly hidden "Shared Exception Lists" Feature.  
By defining host.name as an exception and selecting all the spammy rules (while system Maintenance is done) there are no longer alerts appearing.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 5, 2025, 10:19am UTC](https://discuss.elastic.co/t/how-to-handle-host-specific-maintenance-exceptions-for-siem-security-rules/376584/3 "2025-05-05T10:19:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
