# Pre-built/Community Rules for Monitoring/Observability?

**URL:** <https://discuss.elastic.co/t/pre-built-community-rules-for-monitoring-observability/295165>\
**Category:** Metrics\
**Tags:** elastic-stack-alerting\
**Created:** [January 23, 2022, 9:11pm UTC](https://discuss.elastic.co/t/pre-built-community-rules-for-monitoring-observability/295165 "2022-01-23T21:11:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [January 23, 2022, 9:11pm UTC](https://discuss.elastic.co/t/pre-built-community-rules-for-monitoring-observability/295165/1 "2022-01-23T21:11:50Z")

</div>

Hello All,

I was wonder if Elastic has any plans to offer a repo/project similar to [GitHub - elastic/detection-rules: Rules for Elastic Security's detection engine](https://github.com/elastic/detection-rules), but more for Metrics/Logging/Observability? While I know Kibana provides some base line rules for things like Infrastructure (Hosts/Kubernetes pods) CPU/Memory/Disk/etc.... There isn't much in the way of pre-built rules for other modules that Elastic offers in the observability space. I think that this would be useful with helping provide a baseline for the Alerting tool, for those who may not have the time/expertise to build "good" baseline rules which could be modified to suite the user's environment.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 24, 2022, 12:06pm UTC](https://discuss.elastic.co/t/pre-built-community-rules-for-monitoring-observability/295165/2 "2022-01-24T12:06:15Z")

</div>

Hey @BenB196,

that would indeed be very valuable. The security team is ahead of the curve here with their detection rules implementation.

The idea ultimately is to support this for more than just detection rules through the new "integrations" mechanism, that can be conveniently installed into Elastic Stack deployments via Kibana. The integrations themselves are developed in a public repo ([GitHub - elastic/integrations: Elastic Integrations](https://github.com/elastic/integrations)), which allows for full inspection and community contributions. I think at the moment there are some technical limitations for importing rules (related to actions and API keys IIRC, [Packaged alerts · Issue #67293 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/67293)). But its definitely on our radar: [Add alerts to integration packages · Issue #121 · elastic/package-spec · GitHub](https://github.com/elastic/package-spec/issues/121)

You're welcome to chime in on any of these issues to add more weight to them.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [January 24, 2022, 12:53pm UTC](https://discuss.elastic.co/t/pre-built-community-rules-for-monitoring-observability/295165/3 "2022-01-24T12:53:11Z")

</div>

Hi @weltenwort, thanks for the links to these tickets. I'll read over them and provide my input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2022, 12:53pm UTC](https://discuss.elastic.co/t/pre-built-community-rules-for-monitoring-observability/295165/4 "2022-02-21T12:53:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
