# Signal.rule.name empty?

**URL:** <https://discuss.elastic.co/t/signal-rule-name-empty/260823>\
**Category:** SIEM\
**Created:** [January 12, 2021, 11:04am UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823 "2021-01-12T11:04:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 12, 2021, 11:04am UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/1 "2021-01-12T11:04:07Z")

</div>

Hello,

Just noticed `signal.rule.name` is empty for some rules? Elastic 7.9.2

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e797162b2b546d50581998ef0abfd618174950b4.png)

The above screenshot is from the rule "VNC to the Internet" which I copied from the official " VNC (Virtual Network Computing) to the Internet" rule.

Elastic 7.9.2.

No idea what's causing this.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![Devin\_Hurley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devin_hurley/32/62660_2.png) [@Devin\_Hurley](https://discuss.elastic.co/u/Devin_Hurley)\
**Post date:** [January 13, 2021, 6:23pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/2 "2021-01-13T18:23:39Z")

</div>

Hi @willemdh,

Was this rule created through the UI or via the API? This is a known bug that can occur when a rule is created through the API. [https://github.com/elastic/kibana/issues/81319](https://github.com/elastic/kibana/issues/81319)

Thanks,

Devin

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 13, 2021, 6:58pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/3 "2021-01-13T18:58:56Z")

</div>

Hey @Devin_Hurley,

Thanks for your answer. I created all my rules with the gui.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![Devin\_Hurley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devin_hurley/32/62660_2.png) [@Devin\_Hurley](https://discuss.elastic.co/u/Devin_Hurley)\
**Post date:** [January 13, 2021, 7:42pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/4 "2021-01-13T19:42:22Z")

</div>

Okay interesting. Can you export the "VNC to the Internet" rule and post it here?

Thanks,

Devin

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [January 18, 2021, 6:41pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/5 "2021-01-18T18:41:24Z")

</div>

@Devin_Hurley, @willemdh,

This is a timeline UI bug and not a REST or data problem. I verified it in 7.9.3 and 7.10.2 as well. It looks to be fixed in the upcoming very soon to be released 7.11.0

The rule.name is in the JSON and shows up as columns but not when you search it:

 ![Screen Shot 2021-01-18 at 11.11.02 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65c42869eb820c37fc43a5d4944133856c2850ce.png)

 ![Screen Shot 2021-01-18 at 11.17.09 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/5/05de8d97f89a49d8c4967572c4a0a46b4fc280a8.png)

In the upcoming 7.11.0 where the view of the data is going to be on the right side, it looks like timeline has it fixed. I looked but could not find the PR for this fix though. It might have been fixed along with other bugs:

 ![Screen Shot 2021-01-18 at 11.35.15 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/0/2003a164079ea63f9acfadf02c98ce68490df1a2.png)

I don't see any plans for back-ports for timeline ui for this bug for 7.9.x or 7.10.x at this time but you shouldn't have data loss when you upgrade to 7.11.x after it is released.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [January 18, 2021, 6:46pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/6 "2021-01-18T18:46:16Z")

</div>

@willemdh,

Please verify that you still have `signal.rule.name` in the JSON as I show above and that we're talking about the same bug. As a workaround for 7.9.3 and 7.10.2 you can remove that column by doing a "reset fields" like I do below:

 ![Screen Shot 2021-01-18 at 11.43.59 AM](https://us1.discourse-cdn.com/elastic/original/3X/e/f/ef2814ee5f3a41949c69802f9560e6f101e25249.png)

And then you'll get the word "Rule" with the "rule name" that should be the same as "signal.rule.name" but it's a pretty name and that should work out for you like so:

 ![Screen Shot 2021-01-18 at 11.44.07 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/1/214b1d2d8dbaf3e5bb6579990541a946d4fd1a58.png)

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 18, 2021, 7:08pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/7 "2021-01-18T19:08:22Z")

</div>

Thanks. The value is indeed in the json. Ill patiently wait for Elastic 7.11.

Grtz

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2021, 7:08pm UTC](https://discuss.elastic.co/t/signal-rule-name-empty/260823/8 "2021-02-15T19:08:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
