# SIEM rule not working for custom query

**URL:** <https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895>\
**Category:** SIEM\
**Created:** [October 31, 2020, 9:40am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895 "2020-10-31T09:40:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [October 31, 2020, 9:40am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/1 "2020-10-31T09:40:11Z")

</div>

HI,  
I'm trying to create a simple rule that checks `host.name` field:

 ![Screenshot from 2020-10-31 13-03-44](https://us1.discourse-cdn.com/elastic/original/3X/4/1/413c5cfce495611a7ceee2273f12c83d1c44c7e3.png)  
But no signal is generating. here is my [index mapping](https://gist.github.com/bornatalebi/260675346c7c0a65fc09f76881479558).

I can see events in timeline using the same query.

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 1, 2020, 7:41am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/2 "2020-11-01T07:41:05Z")

</div>

HI @Frank_Hassanabad,  
Sorry for bothering you. I saw [this post](https://discuss.elastic.co/t/detection-custom-rule-not-working/220856) and I thought it might be a problem with my @timestamp too.  
Here's a [sample log](https://gist.github.com/bornatalebi/0310b9b05f43de05450aada4bb8b2b69).  
I posted my mapping in the original post but I don't think that's the problem.  
I'm using a grok processor in ingest pipeline and my patterns don't parse @timestamp field. but it'll have a value after processing.

Any help would be highly appreciated

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [November 1, 2020, 10:36am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/3 "2020-11-01T10:36:54Z")

</div>

hi,  
what user are running as ? Please try as "superadmin" just to see if iti s not related to permissions

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 1, 2020, 10:53am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/4 "2020-11-01T10:53:57Z")

</div>

I'm using the default `superadmin` user, a.k.a **elastic**.  
And I can create the same rule with another index and it works fine.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [November 2, 2020, 6:16pm UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/5 "2020-11-02T18:16:59Z")

</div>

Hi-ya' @borna_talebi,

So I took a look at this and you're in luck ☘ that we have improved the upcoming soon to be released 7.10.0 to bubble up more errors about ECS mapping issues to tighten up this feedback loop about errors from custom source indexes.

In the meantime, I tried out the latest experimental version and here are the two errors I can see in my environment for you to fix and everything should work out:

`host.ip` should be of the data type, "ip" and not "keyword"

 ![Screen Shot 2020-11-02 at 11.04.57 AM](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a58c3002c3187d62eb370f3fba84a0c229c923b9.png)

```auto
"ip": {
  "type": "ip",
  "fields": {
    "keyword": {
      "type": "keyword",
      "ignore_above": 256
    }
  }
},

```

And then second you need to change `user` to be a type of `object` with a `name` underneath it:

 ![Screen Shot 2020-11-02 at 11.06.35 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25ff87a4d44e390513f4d143b48af091b543b34c.png)

```auto
"user": {
  "properties": {
    "name": {
      "type": "keyword"
    }
  }
},

```

I changed both of those and everything worked out w/ the mapping and sample data set you gave me.

ECS references:

> **[User Fields | Elastic Common Schema (ECS) Reference \[1.6\] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-user.html)**

  

> **[Host Fields | Elastic Common Schema (ECS) Reference \[1.6\] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-host.html)**

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 7, 2020, 4:55am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/6 "2020-11-07T04:55:44Z")

</div>

Thanks a lot! It worked!  
Looking forward to 7.10.0 update

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [November 9, 2020, 3:38pm UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/7 "2020-11-09T15:38:49Z")

</div>

Good to hear and thank you for coming back to let the next person know this is what fixed it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2020, 3:38pm UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/8 "2020-12-07T15:38:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
