SIEM Signals not triggering

In the upcoming release we tightened up our error reporting and bubbling up of error messages to help with a lot of these issues.

In the meantime can you post your source index mapping, exported rule(s), and a sample of your data set that you would expect to match which does not and I can run it through our latest and should be able to report back what the issue is.

Also let us know what version of the stack you're using if you could.

1 Like