# Security rules over remote clusters

**URL:** <https://discuss.elastic.co/t/security-rules-over-remote-clusters/311217>\
**Category:** Elasticsearch\
**Created:** [August 2, 2022, 12:25pm UTC](https://discuss.elastic.co/t/security-rules-over-remote-clusters/311217 "2022-08-02T12:25:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Enrico\_Pasqualotto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/enrico_pasqualotto/32/109151_2.png) [@Enrico\_Pasqualotto](https://discuss.elastic.co/u/Enrico_Pasqualotto)\
**Post date:** [August 2, 2022, 12:25pm UTC](https://discuss.elastic.co/t/security-rules-over-remote-clusters/311217/1 "2022-08-02T12:25:37Z")

</div>

Hello, I've setup an infrastructure with a central Elastic cluster and other remote connected using "Remote clusters" feature.  
When I create detection rules I set the index pattern like _:filebeat_ to match events also from remote cluster.  
What about one of this goes offline temporarily?  
I saw a failure on rule like that: Bulk Indexing of signals failed: {"error":{"root\_cause":[{"type":"connect\_transport\_exception","reason":"[192.168.1.199:9300] connect\_exception"}],.....  
and seems rules isn't working anymore.  
Is there a way to run the rule using the connected clusters and ignore the offline ones? I don't want to have all rules stopped until a remote cluster come back online.

Thanks  
Enrico

---

<div class="post-metadata">

**Author:** ![madi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madi/32/75699_2.png) [@madi](https://discuss.elastic.co/u/madi)\
**Post date:** [August 2, 2022, 2:37pm UTC](https://discuss.elastic.co/t/security-rules-over-remote-clusters/311217/2 "2022-08-02T14:37:17Z")

</div>

> [@Enrico\_Pasqualotto](#):
>
> connect\_transport\_exception

Hi @Enrico_Pasqualotto! Thanks for your question. Can you use the `skip_unavailable` flag as documented here? [Search across clusters | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-cross-cluster-search.html#skip-unavailable-clusters)

Hope this helps!  
Madi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2022, 2:37pm UTC](https://discuss.elastic.co/t/security-rules-over-remote-clusters/311217/3 "2022-08-30T14:37:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
