# Rule failure for Windows path exclusions?

**URL:** <https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034>\
**Category:** SIEM\
**Created:** [December 8, 2020, 6:14pm UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034 "2020-12-08T18:14:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 8, 2020, 6:14pm UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034/1 "2020-12-08T18:14:24Z")

</div>

Hello,

Elastic 7.9.2

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bc3e9b5e148ee807fcafae2346cdf8773604a812.png)

Results in:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f008acda1b3eee43319095598a40a18ef220fe3.png)

The working directory values were autocompleted, so this seems weird that this throws an error. When I try to escape the '\' autocomplete does not work.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![madi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madi/32/75699_2.png) [@madi](https://discuss.elastic.co/u/madi)\
**Post date:** [December 9, 2020, 1:03am UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034/2 "2020-12-09T01:03:55Z")

</div>

Hi @willemdh, thanks for posting! This looks like an instance of a known issue: [https://github.com/elastic/kibana/issues/82267](https://github.com/elastic/kibana/issues/82267)

There's a fix slated for the 7.11 release if you're in a position to be able to upgrade. The fix can be tracked here: [https://github.com/elastic/kibana/pull/85051](https://github.com/elastic/kibana/pull/85051)

As for a workaround, if you're not able to target the same process using another field value that doesn't necessitate quotes (i.e. one that doesn't contain a space), you might try creating a custom rule that incorporates this exception into the rule query.

Hope this helps!  
Madi

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 9, 2020, 7:36am UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034/3 "2020-12-09T07:36:31Z")

</div>

Hi @madi,

Thanks for posting the GH links, I'll follow up over there. 🙂

In the meantime I'll create a filter for the rule query instead of an exception, like you suggest.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 9, 2020, 11:11am UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034/4 "2020-12-09T11:11:02Z")

</div>

Fyi, created the following rule filter:

```
{
  "bool": {
    "must": [
      {
        "terms": {
          "process.parent.name": [
            "cmd.exe"
          ]
        }
      },
      {
        "terms": {
          "process.name": [
            "tasklist.exe"
          ]
        }
      },
      {
        "terms": {
          "process.working_directory": [
            "C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\",
            "C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Enterprise\\Common7\\IDE\\"
          ]
        }
      }
    ]
  }
}

```

Which seems to do the job. Thanks @madi

---

<div class="post-metadata">

**Author:** ![madi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madi/32/75699_2.png) [@madi](https://discuss.elastic.co/u/madi)\
**Post date:** [December 9, 2020, 3:26pm UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034/5 "2020-12-09T15:26:20Z")

</div>

Great! Glad you got it sorted, @willemdh!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2021, 3:26pm UTC](https://discuss.elastic.co/t/rule-failure-for-windows-path-exclusions/258034/6 "2021-01-06T15:26:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
