# Matching rule with indicator match error parsing date field

**URL:** <https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171>\
**Category:** SIEM\
**Created:** [October 20, 2021, 9:08am UTC](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171 "2021-10-20T09:08:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [October 20, 2021, 9:08am UTC](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171/1 "2021-10-20T09:08:54Z")

</div>

I create a index that contain all domain that i want to query to according to ecs.  
Now i create a rule that will match any domain query from dns index but it give me this errror:

```auto
An error occurred during rule execution: message: "search_phase_execution_exception: [parse_exception] Reason: failed to parse date field [9223372036854776000] with format [strict_date_optional_time||epoch_millis]: [failed to parse date field [9223372036854776000] with format [strict_date_optional_time||epoch_millis]]" name: "Generic malware domain rule" id: "d4be8a40-147c-11ec-99e8-d50418e566bd" rule id: "a316899b-e2a6-4b38-8d48-4a8f12c3ad14" signals index: ".siem-signals-default"

```

I really dont understand how and why there is a parse error in the date field.  
Please help

Thanks for your time.

---

<div class="post-metadata">

**Author:** ![Michelle\_Bennett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michelle_bennett/32/96142_2.png) [@Michelle\_Bennett](https://discuss.elastic.co/u/Michelle_Bennett)\
**Post date:** [October 20, 2021, 5:05pm UTC](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171/2 "2021-10-20T17:05:23Z")

</div>

What does the mapping in your new index look like for the date field? It is trying to parse the 9223372036854776000 as a date in epoch\_millis and it isn't a valid date. Have a look [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html#date) for a bit of information on mapping dates.

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [October 21, 2021, 2:27am UTC](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171/3 "2021-10-21T02:27:57Z")

</div>

I though that new index does not need date field, since that filed will be like a place to store domain that i want to query so why the need for date field.  
and if i have to have a date field. What field should i have.

---

<div class="post-metadata">

**Author:** ![Michelle\_Bennett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michelle_bennett/32/96142_2.png) [@Michelle\_Bennett](https://discuss.elastic.co/u/Michelle_Bennett)\
**Post date:** [October 21, 2021, 3:16pm UTC](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171/4 "2021-10-21T15:16:01Z")

</div>

The rules engine was meant to run on time series data and uses the @timestamp field as default. There is the ability to change that default to another field under advanced [rule settings.](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rule-ui-advanced-params) When you set the schedule, you are effectively saying, run this rule every X minutes\seconds\etc and look back Y amount of time. The rule uses the @timestamp field to do this. Hopefully this makes sense and I am understanding what you are attempting to do.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2021, 3:16pm UTC](https://discuss.elastic.co/t/matching-rule-with-indicator-match-error-parsing-date-field/287171/5 "2021-11-18T15:16:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
