# Rules in ElasticSIEM not create signals

**URL:** <https://discuss.elastic.co/t/rules-in-elasticsiem-not-create-signals/228068>\
**Category:** SIEM\
**Created:** [April 15, 2020, 9:34am UTC](https://discuss.elastic.co/t/rules-in-elasticsiem-not-create-signals/228068 "2020-04-15T09:34:18Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Nazarenko](https://avatars.discourse-cdn.com/v4/letter/n/b38774/32.png) [@Nazarenko](https://discuss.elastic.co/u/Nazarenko)\
**Post date:** [April 16, 2020, 8:35am UTC](https://discuss.elastic.co/t/rules-in-elasticsiem-not-create-signals/228068/4 "2020-04-16T08:35:31Z")

</div>

Using [https://discuss.elastic.co/t/bulkresponse-had-errors-with-response-statuses-counts-of/226492](https://discuss.elastic.co/t/bulkresponse-had-errors-with-response-statuses-counts-of/226492) i made this. Afther that i see that i have problem with fieds in my index:

 ![Снимок экрана от 2020-04-16 11-27-04](https://us1.discourse-cdn.com/elastic/original/3X/3/1/31be43b4df3a8469c6aa43eabda6c27604a12799.png)  
I changed host field name using logstash, and is workig! 😀

---

_[View the full topic](https://discuss.elastic.co/t/rules-in-elasticsiem-not-create-signals/228068)._
