# SIEM detection engine is not getting started

**URL:** <https://discuss.elastic.co/t/siem-detection-engine-is-not-getting-started/248910>\
**Category:** SIEM\
**Tags:** elastic-stack-machine-learning, detection-rules\
**Created:** [September 17, 2020, 5:48am UTC](https://discuss.elastic.co/t/siem-detection-engine-is-not-getting-started/248910 "2020-09-17T05:48:21Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [September 17, 2020, 7:31pm UTC](https://discuss.elastic.co/t/siem-detection-engine-is-not-getting-started/248910/8 "2020-09-17T19:31:04Z")

</div>

Hmm ok, you seem to be running into issues with the creation and access of the signals index. I know you've likely already run through these things a number of times, but just to confirm:

- HTTP **S** is configured

- In `elasticsearch.yml`, the following is set to true, `xpack.security.enabled`

- In `kibana.yml` the `xpack.encryptedSavedObjects.encryptionKey` is set to any alphanumeric value of 32+ charachters

- Your Kibana space has `All` privileges

- Try adding `create`, `create_doc`, `write`, `index`, `all`, `create_index` privileges for `.siem-signals-*`

---

_[View the full topic](https://discuss.elastic.co/t/siem-detection-engine-is-not-getting-started/248910)._
