# Security Fundamentals: SIEM, Lab 3, Failed to Activate Rule

**URL:** https://discuss.elastic.co/t/security-fundamentals-siem-lab-3-failed-to-activate-rule/292609
**Category:** Elastic Training
**Created:** [December 21, 2021, 7:59pm UTC](https://discuss.elastic.co/t/security-fundamentals-siem-lab-3-failed-to-activate-rule/292609 "2021-12-21T19:59:47Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![csontag](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@csontag](https://discuss.elastic.co/u/csontag)
#### Post date: [December 21, 2021, 7:59pm UTC](https://discuss.elastic.co/t/security-fundamentals-siem-lab-3-failed-to-activate-rule/292609/1 "2021-12-21T19:59:47Z")

</div>

I've made it to the final step of Lab 3 of the "Elastic Security Fundamentals: SIEM". I have been able to successfully complete all of the prior steps up to this point (including installing and configuring the 3 different beat agents), but am finally stuck.

On the final step of Lab 3, Step H, we are to create a custom detection rule. I can follow the instructions to the very end without issue, but when I click "Create & Activate Rule", I am receiving the following error message:

`[feature_not_enabled_exception] api keys are not enabled, with { disabled.feature="api_keys" }`

However, as a student, I do not have access to the /etc/Elasticsearch folder where I think the configuration file for this setting is stored. In addition to not having access to this config file, even if I was able to enable this feature, I would then also need to enable https for Elasticsearch (I think, based on my research for this issue).

Just to test, I was able to create the rule without activating it. If I then navigate to "Manage Detection Rules" and attempt to activate from here using the toggle, I receive the same error message as above.

Am I doing something wrong, or is Step H unable to currently be completed with the current lab configuration?

Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 20, 2022, 8:00pm UTC](https://discuss.elastic.co/t/security-fundamentals-siem-lab-3-failed-to-activate-rule/292609/2 "2022-01-20T20:00:04Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
