# Rule Actions Sometimes Don't Fire

**URL:** <https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245>\
**Category:** Elastic Security\
**Created:** [July 12, 2023, 4:01pm UTC](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245 "2023-07-12T16:01:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SomeRobot](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Post date:** [July 12, 2023, 4:01pm UTC](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245/1 "2023-07-12T16:01:08Z")

</div>

We have hundreds of rules created in Elastic Security which we are leveraging as our SIEM, many Elastic created, some are ours. These rules are all configured to perform the same action, which is to send some details to a webhook we have that integrates with our ticketing system and SOAR. This works fine 99% of the time. However, periodically we notice that a Rule fires, and the corresponding action does not. There is no indication our webhook has received the event, no error, no nothing. Obviously this is an issue as it could mean our analysts miss security events. Has anyone noticed this issue before? We notice this on Elastic rules as well as our own. For instance, yesterday a 'Privileged Account Brute Force' rule triggered 4 times, and we received no alert to our webhook \*and have received webhooks for these before and since. We checked the webhook, and it was not down or refusing requests at this time. We have a script that runs to check the webhook is able to receive events and it was successfully receiving events at that time, so this must be an Elastic issue.

Is there a place these actions are logged in Elastic? Any way to troubleshoot this?

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [July 12, 2023, 5:05pm UTC](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245/2 "2023-07-12T17:05:13Z")

</div>

Hi @SomeRobot ,

What version are you on? We log all action activity (including errors) in the stack management rule page. Just ensure you have the correct columns added.

Example below:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/8/48739ceee35fd8582fbf0bcb502305186d3d7315.jpeg)

---

<div class="post-metadata">

**Author:** ![SomeRobot](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Post date:** [July 12, 2023, 5:49pm UTC](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245/3 "2023-07-12T17:49:06Z")

</div>

Exactly what I was looking for, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2023, 5:49pm UTC](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245/4 "2023-08-09T17:49:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
