# Not able to edit rules

**URL:** <https://discuss.elastic.co/t/not-able-to-edit-rules/314643>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [September 18, 2022, 12:25pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643 "2022-09-18T12:25:25Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [September 18, 2022, 12:25pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/1 "2022-09-18T12:25:25Z")

</div>

Hi,  
after updating from 8.2.3 to 8.4 it's no longer possible to edit the existing rules.  
Every time "Object type "siem.queryRule" is not registered." is shown.  
Hope somebody has an idea how to fix.

another error occures:

> {  
> "name": "Error",  
> "body": {  
> "message": "illegal\_argument\_exception: rollover target [.siem-signals-default] does not point to a write index",  
> "status\_code": 400  
> },  
> "message": "Bad Request",  
> "stack": "o@[https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:396:16044\nt@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:396:15274\n\_\_kbnSharedDeps\_npm\_\_](https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:396:16044%5Cnt@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:396:15274%5Cn __kbnSharedDeps_npm__ )\</e.exports/\<@[https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:396:12404\nn@https://fed:5601/55434/bundles/core/core.entry.js:1:269671\ne/](https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:396:12404%5Cnn@https://fed:5601/55434/bundles/core/core.entry.js:1:269671%5Cne/)\<@[https://fed:5601/55434/bundles/core/core.entry.js:1:276516\nf@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:515:1458\nd/o.\_invoke](https://fed:5601/55434/bundles/core/core.entry.js:1:276516%5Cnf@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:515:1458%5Cnd/o._invoke)\</\<@[https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:515:1212\nO/](https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:515:1212%5CnO/)\</\<@[https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:515:1821\nn@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:364:292131\ns@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:364:292343\n](https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:515:1821%5Cnn@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:364:292131%5Cns@https://fed:5601/55434/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:364:292343%5Cn)"  
> }

best regards  
Uwe

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [September 18, 2022, 1:27pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/2 "2022-09-18T13:27:44Z")

</div>

@UweW - Hi there,

Can you run `GET _cat/aliases/.siem-signals-*?v` and `GET _cat/shards/.siem-signals-*?v` and share the results with us?

Thank you.

---

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [September 18, 2022, 2:25pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/3 "2022-09-18T14:25:44Z")

</div>

Hi Romain,

> `GET _cat/aliases/.siem-signals-*?v`  
> alias index filter routing.index routing.search is\_write\_index  
> .siem-signals-default .siem-signals-default-000010 - - - false  
> .siem-signals-default .siem-signals-default-000011 - - - false

> `GET _cat/shards/.siem-signals-*?v`  
> index shard prirep state docs store ip node  
> .siem-signals-default-000010 0 p STARTED 2 48.5kb 10.88.0.1 elasticsearch  
> .siem-signals-default-000011 0 p STARTED 963 958.5kb 10.88.0.1 elasticsearch

best regards  
Uwe

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [September 19, 2022, 8:55am UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/4 "2022-09-19T08:55:42Z")

</div>

Hi @UweW - could you run this and check if this solves the problem?

```auto
POST _aliases
{
  "actions": [
    {
      "add": {
        "index": ".siem-signals-default-000011",
        "alias": ".siem-signals-default",
        "is_write_index": true
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [September 19, 2022, 4:50pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/5 "2022-09-19T16:50:12Z")

</div>

> [@ropc](#):
>
> `GET _cat/aliases/.siem-signals-*?v`

Hey there!

The `.siem-signals` index was the index name used pre-8.0 for writing security solution alerts. In 8.0 it's expected that it is now aliased to the new security solution alerts index, so

`GET _cat/aliases/.siem-signals-*?v`

should result in something like:

```auto
alias index filter routing.index routing.search is_write_index
.siem-signals-default .internal.alerts-security.alerts-default-000001 - - - false

```

This should have all occurred in the initial upgrade to 8.x.

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [September 19, 2022, 4:59pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/6 "2022-09-19T16:59:13Z")

</div>

@UweW

If you `GET /.siem-signals*` - can you share what the top portion of that return looks like. We would expect to see something like:

```auto
{
  ".internal.alerts-security.alerts-default-000001": {
    "aliases": {
      ".alerts-security.alerts-default": {
        "is_write_index": false
      },
      ".siem-signals-default": {
        "is_write_index": false
      }
    },
    "mappings": {
      "dynamic": "false",
      "_meta": {
        "namespace": "default",
        "kibana": {
          "version": "8.4.2"
        }
      },
[...]

```

In 8.x we should no longer be writing to `.siem-signals*`.

Best,  
Yara

---

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [September 19, 2022, 6:54pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/7 "2022-09-19T18:54:36Z")

</div>

Hi Romain,  
that fixed the issue that I was not able to edit the rules in the security section. 👍  
There is still the issue with the "Object type "siem.queryRule" is not registered." when I open rules in the stack management section .

best regards  
Uwe

---

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [September 19, 2022, 7:02pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/8 "2022-09-19T19:02:44Z")

</div>

Hi Yara,  
this is how it looks:

> {  
> ".siem-signals-default-000010": {  
> "aliases": {  
> ".alerts-security.alerts-default": {  
> "is\_write\_index": false  
> },  
> ".siem-signals-default": {  
> "is\_write\_index": false  
> }  
> },  
> "mappings": {  
> "dynamic": "false",  
> "\_meta": {  
> "version": 45,  
> "aliases\_version": 3  
> },  
> "runtime": {  
> "host.os.name.caseless": {  
> "type": "keyword",  
> "script": {  
> "source": "if(doc['host.os.name'].size()!=0) emit(doc['host.os.name'].value.toLowerCase());",  
> "lang": "painless"  
> }  
> }  
> },

best regards  
Uwe

---

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [September 19, 2022, 7:21pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/9 "2022-09-19T19:21:10Z")

</div>

Hi Yara,  
I cannot find any index beginning with .internal\*  
So it looks like that it hasn't occured in the initial upgrade.  
One more time updating was not successful ☹  
Any idea how to fix ?  
Best regrads  
Uwe

PS: the update path was 8.3.3 -\> 8.4.0 -\> 8.4.1

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [September 19, 2022, 8:26pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/10 "2022-09-19T20:26:15Z")

</div>

@UweW the `.internal` index is created once the first alert is written. That may be why you don't see it yet. If rules are running but no alerts have been generated, it won't yet exist.

As for the issues with viewing rules in stack management - I am asking around to see if it's a known issue. Luckily, most all actions you would need to take can be done through the security solution rules management interface.

I'll follow back around as soon as I hopefully find out more on the stack management side 🙂

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [September 20, 2022, 12:44am UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/11 "2022-09-20T00:44:41Z")

</div>

Here is the issue that was tracked for this error you're encountering - [Security Rule details page doesn't load up in Stack Management · Issue #138639 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/138639)

It looks like it may not have made it in 8.4.1, but is in for 8.4.2.

---

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [September 20, 2022, 5:01pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/12 "2022-09-20T17:01:39Z")

</div>

Hi Yara,  
yes, this is the issue I have.  
8.4.2 was released today. Even if I can't find a hint in the release notes I can confirm that it fixes this bug on two Lab installations.  
Many thanks for your support.

Uwe

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2022, 5:02pm UTC](https://discuss.elastic.co/t/not-able-to-edit-rules/314643/13 "2022-10-18T17:02:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
