The only thing I could think of that might work in Elastic is to adjust the lookback time on when a rule is run or build visualizations that match the detection query and run your logs against the visualization in Kibana.
There are a few alternatives that can run SIGMA rules against event log files. You could convert your detection rules to SIGMA and then run your logs against those rules.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.