# Indicator Match - Rule Type: Correlation - Not Match Result Un Available

**URL:** <https://discuss.elastic.co/t/indicator-match-rule-type-correlation-not-match-result-un-available/301734>\
**Category:** Elastic Search\
**Created:** [April 6, 2022, 9:48am UTC](https://discuss.elastic.co/t/indicator-match-rule-type-correlation-not-match-result-un-available/301734 "2022-04-06T09:48:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![raghulannadurai](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@raghulannadurai](https://discuss.elastic.co/u/raghulannadurai)\
**Post date:** [April 6, 2022, 9:48am UTC](https://discuss.elastic.co/t/indicator-match-rule-type-correlation-not-match-result-un-available/301734/1 "2022-04-06T09:48:29Z")

</div>

Good day to you all.

Hope the below example can give you more context to the request,

Let us consider the below,

1. we have a three document doc1, doc2 and doc3.
2. doc1 and doc2 were indexed into a index name A (firewall index)
3. doc 3 was indexed into a index name B (threat feed index)

doc1 in JSON

```auto
       {
            "_index": "A",
            "_type": "firewall",
            "_id": "1",
            "domain": "test.com",
            "dstport": "80",
            "srcport": "22000"  
        }

```

doc2 in JSON

```auto
       {
            "_index": "A",
            "_type": "firewall",
            "_id": "2",
            "domain": "test1.com",
            "dstport": "443",
            "srcport": "11000"  
        }

```

doc3 in JSON

```auto
       {
            "_index": "B",
            "_type": "threatfeed",
            "_id": "3",
            "ioc": "test1.com"
        }

```

We wanted to create a rule/query to trigger an alert or to create visualization using "not match" condition by correlating Index A (Field - domain) and Index B (Field - ioc), i.e., from the above example we expect the result as "domain: [test.com](http://test.com)" - doc1 to be triggered as an alert or to be called in a visualization, as it does not match the condition.

We tried to achieve this using the rule type "Indicator match" but, it has the "match" option but "not match" option is not available. -Attached the screenshot for reference.

Do we have the feature available in elastic or any other work around to achieve this usecase?

---

<div class="post-metadata">

**Author:** ![Byron\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/byron_h/32/82245_2.png) [@Byron\_H](https://discuss.elastic.co/u/Byron_H)\
**Post date:** [April 12, 2022, 4:30pm UTC](https://discuss.elastic.co/t/indicator-match-rule-type-correlation-not-match-result-un-available/301734/2 "2022-04-12T16:30:39Z")

</div>

Hi Raghul,

You may have posted this in the wrong forum section. This is for [Elastic Enterprise Search](https://www.elastic.co/enterprise-search/) but I think this question may be more relevant to [Elastic Security](https://discuss.elastic.co/c/security/83)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:35am UTC](https://discuss.elastic.co/t/indicator-match-rule-type-correlation-not-match-result-un-available/301734/3 "2022-11-04T08:35:02Z")

</div>


