# On demand Rule execution

**URL:** <https://discuss.elastic.co/t/on-demand-rule-execution/371818>\
**Category:** Elastic Security\
**Created:** [December 11, 2024, 9:42am UTC](https://discuss.elastic.co/t/on-demand-rule-execution/371818 "2024-12-11T09:42:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kuly2Fraise](https://avatars.discourse-cdn.com/v4/letter/k/f14d63/32.png) [@Kuly2Fraise](https://discuss.elastic.co/u/Kuly2Fraise)\
**Post date:** [December 11, 2024, 9:42am UTC](https://discuss.elastic.co/t/on-demand-rule-execution/371818/1 "2024-12-11T09:42:37Z")

</div>

Hello,

I have a rule in Kibana that counts the number of packets received for a given `wlan-src` every second. This is the current setup:

- Custom query: `event.wlan-src: *`
- Runs every 1 second
- Threshold: 63 packets

 ![2024-12-11_10h22_41](https://us1.discourse-cdn.com/elastic/original/3X/6/0/602a9a08c9c807174bf388e6aa05bf811c18af39.png)

However, I would like to modify this rule so that it execute the rule **only when a new packet** with the field `event.wlan-src` arrives, rather than continuously counting the packets. Is it technically possible to set up such a rule in Kibana without requiring a paid license?

Any help or guidance would be appreciated!

Thank you!

---

<div class="post-metadata">

**Author:** ![Nikita\_Khristinin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikita_khristinin/32/102092_2.png) [@Nikita\_Khristinin](https://discuss.elastic.co/u/Nikita_Khristinin)\
**Post date:** [December 11, 2024, 10:09am UTC](https://discuss.elastic.co/t/on-demand-rule-execution/371818/2 "2024-12-11T10:09:39Z")

</div>

Hello!

I think what you are looking for is a New Terms rule

> **[Create a detection rule | Elastic Security Solution \[8.16\] | Elastic](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-new-terms-rule)**

---

<div class="post-metadata">

**Author:** ![Kuly2Fraise](https://avatars.discourse-cdn.com/v4/letter/k/f14d63/32.png) [@Kuly2Fraise](https://discuss.elastic.co/u/Kuly2Fraise)\
**Post date:** [December 11, 2024, 10:28am UTC](https://discuss.elastic.co/t/on-demand-rule-execution/371818/3 "2024-12-11T10:28:27Z")

</div>

Thanks for your answer!

But I'm not sure that's what I want, as the description of a ‘new Term rule’ is that we want to detect new packets.

Here, I want the rule to run each time a new packet meets the conditions. Basically, if I don't receive a matching packet for 10 hours, I don't want the rule to run.

---

<div class="post-metadata">

**Author:** ![Nikita\_Khristinin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikita_khristinin/32/102092_2.png) [@Nikita\_Khristinin](https://discuss.elastic.co/u/Nikita_Khristinin)\
**Post date:** [December 11, 2024, 10:55am UTC](https://discuss.elastic.co/t/on-demand-rule-execution/371818/4 "2024-12-11T10:55:47Z")

</div>

Thanks for the explanation!

Our security rules, can't run on demand at the moment.

Rules will always run depending on the interval you configured.

Also, I noticed that you run the rule every 1s + plus 1 minute lookback time.

Like rule executed:

1. Rule executed at 12:30:00 - will search data from 12:28:59-12:30:00
2. Next rule executed 12:30:01 - will search data from 12:29:00-12:30:01
3. Next rule executed 12:30:02 - will search data from 12:29:01-12:30:02

Depends on your cluster and amount of rules, but this configuration can cause performance problems in the future if you have a lot of rules like that.

But maybe you will give us more context about your use case, and we will try to find a better solution with our rules.

---

<div class="post-metadata">

**Author:** ![Kuly2Fraise](https://avatars.discourse-cdn.com/v4/letter/k/f14d63/32.png) [@Kuly2Fraise](https://discuss.elastic.co/u/Kuly2Fraise)\
**Post date:** [December 11, 2024, 11:55am UTC](https://discuss.elastic.co/t/on-demand-rule-execution/371818/5 "2024-12-11T11:55:21Z")

</div>

Thanks for your reply. I just wanted to know if it was possible for my project.

It would be nice to implement it 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2025, 11:55am UTC](https://discuss.elastic.co/t/on-demand-rule-execution/371818/6 "2025-01-08T11:55:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
