# Just a question about a siem rule filter

**URL:** <https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397>\
**Category:** SIEM\
**Created:** [November 23, 2020, 8:11pm UTC](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397 "2020-11-23T20:11:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 23, 2020, 8:11pm UTC](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397/1 "2020-11-23T20:11:17Z")

</div>

Hello,

Just wondering what's the purpose of the extra info / metadata in the filter of for example:

> <https://github.com/elastic/detection-rules/blob/main/rules/apm/apm_null_user_agent.toml>

I can't find this info in the SIEM rule when I duplicate it:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4577856b6c6e12f08ae22dd01db8608522280bab.png)

```
{
    "$state": {
        "store": "appState"
    },
    "exists": {
        "field": "user_agent.original"
    },
    "meta": {
        "disabled": false,
        "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index",
        "key": "user_agent.original",
        "negate": true,
        "type": "exists",
        "value": "exists"
    }
}

```

What does the meta and $state do exactly? And why can't I find this info in the rule configuration?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)\
**Post date:** [November 24, 2020, 10:58pm UTC](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397/2 "2020-11-24T22:58:27Z")

</div>

Hi @willemdh,

The `meta` and `$state` entries are used to serialize and deserialize the state of the search bar filters shown in the **Custom query** section of the rule configuration.

Let's explore how the JSON in the previous post maps to the screenshot of the rule configuration:

- the value of the `key` entry in the `meta` section of the JSON:

```auto
"key": "user_agent.original"

```

corresponds with the search bar filter's **Field** `user_agent.original` in the screenshot you provided (👀 focus on the **EDIT FILTER** popover):

> [@willemdh](#):
>
> ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4577856b6c6e12f08ae22dd01db8608522280bab.png)

- the value for the `type` entry in the `meta` section of the JSON:

```auto
"type": "exists",

```

is combined with the `negate` entry (also in the `meta` section of the JSON):

```auto
"negate": true,

```

to become **Operator** `does not exist` in the screenshot:

> [@willemdh](#):
>
> ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4577856b6c6e12f08ae22dd01db8608522280bab.png)

Thanks for your question!

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 26, 2020, 9:11pm UTC](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397/3 "2020-11-26T21:11:05Z")

</div>

Hello @Andrew_G,

Thanks a lot for the detailed explanation. Just to get to the bottom of this...

> (👀 focus on the **EDIT FILTER** popover):

When I click 'Edit filter' I do not see the meta and $state keys:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7e5ba9c37c3f44059e538de1bb05e424cdbb40b.png)

This is normal right? (The rule has been duplicated and edited, but I did not touch this filter)

I just find it weird that pasting

```
{
  "exists": {
    "field": "user_agent.original"
  }
}

```

Seems to have the same result as pasting

```
{
    "$state": {
        "store": "appState"
    },
    "exists": {
        "field": "user_agent.original"
    },
    "meta": {
        "disabled": false,
        "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index",
        "key": "user_agent.original",
        "negate": true,
        "type": "exists",
        "value": "exists"
    }
}

```

After saving any of the above and going back to 'Edit filter', I always see:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/0/40784a664c45639932b31cd79740473e149dabf4.png)

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)\
**Post date:** [November 30, 2020, 3:55pm UTC](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397/4 "2020-11-30T15:55:27Z")

</div>

> [@willemdh](#):
>
> When I click 'Edit filter' I do not see the meta and $state keys:
> 
> ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7e5ba9c37c3f44059e538de1bb05e424cdbb40b.png)
> 
> This is normal right? (The rule has been duplicated and edited, but I did not touch this filter)

Yes, this is normal; the `meta` and `$state` fields are internal, and not intended to be editable via the UI.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2020, 3:55pm UTC](https://discuss.elastic.co/t/just-a-question-about-a-siem-rule-filter/256397/5 "2020-12-28T15:55:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
