# Indicator Match rule not generating alerts (Basic license, self-managed 9.3.0)

**URL:** <https://discuss.elastic.co/t/indicator-match-rule-not-generating-alerts-basic-license-self-managed-9-3-0/385726>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [April 1, 2026, 7:34am UTC](https://discuss.elastic.co/t/indicator-match-rule-not-generating-alerts-basic-license-self-managed-9-3-0/385726 "2026-04-01T07:34:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![arav](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@arav](https://discuss.elastic.co/u/arav)\
**Post date:** [April 1, 2026, 7:34am UTC](https://discuss.elastic.co/t/indicator-match-rule-not-generating-alerts-basic-license-self-managed-9-3-0/385726/1 "2026-04-01T07:34:13Z")

</div>

Hi all,

I am running a self-managed Elastic Stack (v9.3.0) with a **Basic license**.

I have ingested threat intelligence data from MISP using the official integration, and I am trying to create an **Indicator Match rule** in Elastic Security.

### What I did

- Created a test event document with:

- Verified that the same IP exists in the MISP TI index:

- Confirmed both documents are searchable in Discover and via Dev Tools

- Created an Indicator Match rule with:

### What is happening

- Rule runs successfully (no visible errors)

- No alerts are generated

- Even when using a simplified lab setup (same index, same value), still no alerts

### What I have already checked

- Data is present and searchable

- Field values match exactly

- Mapping types aligned (tested both `ip` and `keyword`)

- Time range is correct

- Rule is enabled and executed

### Question

Is this expected behavior under the **Basic license**?

Do Indicator Match rules require a higher license tier (e.g., Trial / Platinum) to generate alerts?

Any clarification would be appreciated.

Thanks!

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [April 16, 2026, 7:27pm UTC](https://discuss.elastic.co/t/indicator-match-rule-not-generating-alerts-basic-license-self-managed-9-3-0/385726/2 "2026-04-16T19:27:09Z")

</div>

@arav no, licensing should not be an issue here, I don't think 👍 .

My first thought is that this _sounds_ like either a mapping or timing issue, so let's try to gather a little more data in those regards:

1. Can you share a full (without sharing any sensitive information, of course) rule definition for the rule in question? That would help complete the picture of what might be happening, here.

2. Can you confirm the mappings on both indices by sharing the results of [GET mappings](https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-indices-get-mapping) responses for both the source and indicator index patterns? E.g. `GET /{threat_index_pattern/_mapping/field/destination.ip`

3. If you have examples of both a source document and a indicator document that you think should be matching but aren't, those would also be helpful information.

I think between those three things, we can narrow down on a root cause here. 👍
