# SIEM rule not working for custom query

**URL:** <https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895>\
**Category:** SIEM\
**Created:** [October 31, 2020, 9:40am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895 "2020-10-31T09:40:11Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 1, 2020, 7:41am UTC](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895/2 "2020-11-01T07:41:05Z")

</div>

HI @Frank_Hassanabad,  
Sorry for bothering you. I saw [this post](https://discuss.elastic.co/t/detection-custom-rule-not-working/220856) and I thought it might be a problem with my @timestamp too.  
Here's a [sample log](https://gist.github.com/bornatalebi/0310b9b05f43de05450aada4bb8b2b69).  
I posted my mapping in the original post but I don't think that's the problem.  
I'm using a grok processor in ingest pipeline and my patterns don't parse @timestamp field. but it'll have a value after processing.

Any help would be highly appreciated

---

_[View the full topic](https://discuss.elastic.co/t/siem-rule-not-working-for-custom-query/253895)._
