# Security alerts not generated for each document

**URL:** https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049
**Category:** Elastic Security
**Created:** [August 17, 2023, 6:39pm UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049 "2023-08-17T18:39:26Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![nlcsdev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nlcsdev/32/124524_2.png) [@nlcsdev](https://discuss.elastic.co/u/nlcsdev)
#### Post date: [August 17, 2023, 6:39pm UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049/1 "2023-08-17T18:39:27Z")

</div>

I have a processor that sends vulnerability reports to an index, and thousands of documents can be ingested within seconds. I've set up an alert through security using custom query, where the query just filters for documents of a high risk score.

Expectation:  
I see 500+ documents meeting the query requirements within the look back time, so I expect 500+ alerts.

Result:  
I get a mixture of 300-400+ alerts every time I ingest the documents. I ran the same ingestion every hour to ensure the look back is on working on documents that got ingested together. Sometimes I get 100 alerts every interval until it reaches 300-400+ alerts total, when I increase Kibana's memory, I was able to get a lump sum of 300-400+ alerts in one interval, but the number of alerts I get are not consistent nor do they match the number of expected alerts (1:1 to qualified documents).

Additional information:  
I suspected some documents may be ill formatted, so I indexed a singular document that wasn't alerted and that showed up on its own. So the documents are formatted properly and ECS compliant.

Cluster is setup with default ECK Helm 2.9.0, Elasticsearch and Kibana at 8.9.0.

I am not sure what might be causing this issue, or if it is a know issue (can't find other mentions), or if alerting for thousands of documents that were ingested at virtually the same time on a per document basis is not an intended functionality of the security alert.

---

<div class="post-metadata">

### Author: ![dplumlee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dplumlee/32/101403_2.png) [@dplumlee](https://discuss.elastic.co/u/dplumlee)
#### Post date: [August 17, 2023, 7:47pm UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049/2 "2023-08-17T19:47:23Z")

</div>

Hi @nlcsdev,

If you are expecting 500 alerts every rule run, I would expand the `max_signals` [field](https://www.elastic.co/guide/en/security/current/rules-api-create.html#opt-fields-all) on the rule in question if you haven't done so already. Perhaps to 500 or 1000, something in that ballpark. It defaults to 100 which is probably why you're seeing the chunks of 100 every interval. Besides that, do you know if your data has a lot of docs with identical timestamps? Might help to triage where the issue you're facing is

---

<div class="post-metadata">

### Author: ![nlcsdev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nlcsdev/32/124524_2.png) [@nlcsdev](https://discuss.elastic.co/u/nlcsdev)
#### Post date: [August 17, 2023, 8:14pm UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049/3 "2023-08-17T20:14:03Z")

</div>

I have increased the `max_signals` to 1000 before already.

I didn't look too closely at the timestamp but I would suspect a lot of documents are since many of them are all bulk created at once. Would that be a problem?

---

<div class="post-metadata">

### Author: ![dplumlee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dplumlee/32/101403_2.png) [@dplumlee](https://discuss.elastic.co/u/dplumlee)
#### Post date: [August 17, 2023, 9:27pm UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049/4 "2023-08-17T21:27:03Z")

</div>

We have a current known issue that can cause problems when sets of documents have the same timestamp. We're currently writing up a github issue I'll link soon, but the best workaround currently is to ensure each document has a unique timestamp. Are you using a [timestamp override](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rule-ui-advanced-params) field in your rule definition? If you are, the field you'll want to check will be based on that configuration, otherwise it'll be the `@timestamp` field.

Also when updating rules through the UI (editing the rule and saving changes), `max_signals` is reset to 100 so double check the rule object to see if it's what you expect it to be.

---

<div class="post-metadata">

### Author: ![dplumlee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dplumlee/32/101403_2.png) [@dplumlee](https://discuss.elastic.co/u/dplumlee)
#### Post date: [August 17, 2023, 9:53pm UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049/5 "2023-08-17T21:53:34Z")

</div>

We are tracking that issue I referenced here: [[Security Solution][Detection Engine] When sets of documents have identical timestamps, they can potentially be skipped during alert creation · Issue #164233 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/164233)

---

<div class="post-metadata">

### Author: ![nlcsdev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nlcsdev/32/124524_2.png) [@nlcsdev](https://discuss.elastic.co/u/nlcsdev)
#### Post date: [August 18, 2023, 4:00am UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049/6 "2023-08-18T04:00:44Z")

</div>

I see, thanks for pointing this out and linking the issue. I'll mark this as the solution for now as it resolves all my confusion around this issue.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 15, 2023, 4:00am UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049/7 "2023-09-15T04:00:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
