# Severity override range

**URL:** <https://discuss.elastic.co/t/severity-override-range/268064>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [March 23, 2021, 9:19am UTC](https://discuss.elastic.co/t/severity-override-range/268064 "2021-03-23T09:19:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![buzzdeee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/buzzdeee/32/12703_2.png) [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Post date:** [March 23, 2021, 9:19am UTC](https://discuss.elastic.co/t/severity-override-range/268064/1 "2021-03-23T09:19:50Z")

</div>

Hi,

I'm running ELK stack version 7.11.2.

I want to ingest AWS GuardDuty alerts, these have severities defined:

[https://docs.aws.amazon.com/guardduty/latest/ug/guardduty\_findings.html](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings.html)

basically values between 1.0 and 8.9 mapping to different severity rules.  
These I've mapped to event.severity.

Now for signal rule detection, I wanted to override the default severity,  
and was wondering how to give a range in order to map the GuardDuty  
severities to Kibana SIEM severities?

I could do so in Logstash, create a new field, and use that in the severity  
override, but thought there might be a way to do so in Kibana?

Sebastian

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2021, 9:20am UTC](https://discuss.elastic.co/t/severity-override-range/268064/2 "2021-04-20T09:20:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
