# Multiple Alerts in Different ATT&CK Tactics on a Single Host

**URL:** <https://discuss.elastic.co/t/multiple-alerts-in-different-att-ck-tactics-on-a-single-host/379248>\
**Category:** Elastic Security\
**Created:** [June 17, 2025, 1:48pm UTC](https://discuss.elastic.co/t/multiple-alerts-in-different-att-ck-tactics-on-a-single-host/379248 "2025-06-17T13:48:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [June 17, 2025, 1:48pm UTC](https://discuss.elastic.co/t/multiple-alerts-in-different-att-ck-tactics-on-a-single-host/379248/1 "2025-06-17T13:48:24Z")

</div>

I wonder how to handle this kind of alert.

Out of documentation i shall "investigate in timeline" to see what in detail triggered the alert. Well - my timeline is empty?

Also in the alert data there's no more info about the source.

So what am i missing? How can i get the events that triggered this alert?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [June 18, 2025, 5:06am UTC](https://discuss.elastic.co/t/multiple-alerts-in-different-att-ck-tactics-on-a-single-host/379248/2 "2025-06-18T05:06:51Z")

</div>

Hello @GKre

I believe to review this we will have to check the Rule logic & try to search the data in the corresponding index/dataview at the time of alert with the logic applied in the Rule to understand why the alert was triggered & its corresponding events.

In future to make this analysis easy you can try to index this data as part of Action into an Index (alerts-analysis) any name, which could have more data from the {{context}} field as per your requirement.

Thanks!!

---

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [June 18, 2025, 8:05am UTC](https://discuss.elastic.co/t/multiple-alerts-in-different-att-ck-tactics-on-a-single-host/379248/3 "2025-06-18T08:05:12Z")

</div>

Thank you @Tortoise,  
if i check your "solution path" we have relevant base information like the host and the time frame in the alert. The "logic" is also available as part of the rule definition.  
Would it be possible to automatically create a "query" for this so that i could directly go into investigation without as first step do manual tasks?  
This could speed up the process?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [June 18, 2025, 10:56am UTC](https://discuss.elastic.co/t/multiple-alerts-in-different-att-ck-tactics-on-a-single-host/379248/4 "2025-06-18T10:56:56Z")

</div>

Hello @GKre

Please review below blog :

> [@Elasticsearch query dsl alert rule to discover search object](https://discuss.elastic.co/t/elasticsearch-query-dsl-alert-rule-to-discover-search-object/378615/4):
>
> Thanks @Baba_Kourouma for the details. Please review steps provided in below blog : Thanks!!

Thanks!!
