# Security Rules with Endgame get an error

**URL:** <https://discuss.elastic.co/t/security-rules-with-endgame-get-an-error/317241>\
**Category:** Endpoint Security\
**Created:** [October 22, 2022, 8:05am UTC](https://discuss.elastic.co/t/security-rules-with-endgame-get-an-error/317241 "2022-10-22T08:05:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hermlam](https://avatars.discourse-cdn.com/v4/letter/h/8797f3/32.png) [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Post date:** [October 22, 2022, 8:05am UTC](https://discuss.elastic.co/t/security-rules-with-endgame-get-an-error/317241/1 "2022-10-22T08:05:31Z")

</div>

Hi,

In Elastic Security there are 4 rules which don’t work because Endgame is replaced by Endpoint. The rules are:

- Malware - Detected - Elastic Endgame
- Malware - Prevented - Elastic Endgame
- Ransomware - Detected - Elastic Endgame
- Ransomware - Prevented - Elastic Endgame

These rules get the following error:

“This rule is attempting to query data from Elasticsearch indices listed in the "Index pattern" section of the rule definition, however no index matching: ["endgame-\*"] was found.”

I can make a clone of the rules and change the index to ‘endpoint-\*’ , but I think the fieldnames do not look the same.

Any ideas? Or better, let Elastic distribute new rules for these.

Thanks,

Herman

---

<div class="post-metadata">

**Author:** ![justin\_ibarra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_ibarra/32/110828_2.png) [@justin\_ibarra](https://discuss.elastic.co/u/justin_ibarra)\
**Post date:** [October 24, 2022, 8:03pm UTC](https://discuss.elastic.co/t/security-rules-with-endgame-get-an-error/317241/2 "2022-10-24T20:03:14Z")

</div>

Hey Herman 👋 ,

These rules are intended to be promotion rules for users still using the endgame sensor and platform (as opposed to using the endpoint sensor). The raw endgame logs and alerts get logged to the specified `endgame-*` indexes, so this is to create alerts in the security app.

Essentially, if you are an endpoint user, you can effectively ignore them.

Justin

---

<div class="post-metadata">

**Author:** ![hermlam](https://avatars.discourse-cdn.com/v4/letter/h/8797f3/32.png) [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Post date:** [October 25, 2022, 3:04pm UTC](https://discuss.elastic.co/t/security-rules-with-endgame-get-an-error/317241/3 "2022-10-25T15:04:46Z")

</div>

Hi Justin,

Thanks for your answer. I understand that the mentioned use cases are only for Endgame users. But I am wondering if there are the same 4 for Endpoint Users?

So does our SIEM detect ramson- and malware and report about it? I don’t see those Use Cases.

Thanks,

Herman

---

<div class="post-metadata">

**Author:** ![justin\_ibarra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_ibarra/32/110828_2.png) [@justin\_ibarra](https://discuss.elastic.co/u/justin_ibarra)\
**Post date:** [October 25, 2022, 3:30pm UTC](https://discuss.elastic.co/t/security-rules-with-endgame-get-an-error/317241/4 "2022-10-25T15:30:58Z")

</div>

Yes it does - refer to this [rule](https://github.com/elastic/detection-rules/blob/main/rules/integrations/endpoint/elastic_endpoint_security.toml)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2022, 3:31pm UTC](https://discuss.elastic.co/t/security-rules-with-endgame-get-an-error/317241/5 "2022-11-22T15:31:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
