# Unable to observe Security alerts in Elastic Security

**URL:** <https://discuss.elastic.co/t/unable-to-observe-security-alerts-in-elastic-security/349502>\
**Category:** Elastic Security\
**Created:** [December 17, 2023, 7:48am UTC](https://discuss.elastic.co/t/unable-to-observe-security-alerts-in-elastic-security/349502 "2023-12-17T07:48:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 17, 2023, 7:48am UTC](https://discuss.elastic.co/t/unable-to-observe-security-alerts-in-elastic-security/349502/1 "2023-12-17T07:48:17Z")

</div>

Dear Team,

I have setup a test environment on elastic cloud and i am ingesting windows events.  
I created an index with below mapping

PUT alerts-security  
{  
"settings" : {  
"number\_of\_shards" : 1  
},  
"mappings" : {  
"properties" : {  
"rule\_id" : { "type" : "text" },  
"rule\_name" : { "type" : "text" },  
"alert\_id" : { "type" : "text" },  
"context\_message": { "type" : "text" },  
"@timestamp": { "type" : "date" }  
}  
}  
}

afterwards created an aliases for the index

POST \_aliases  
{  
"actions": [  
{  
"add": {  
"index": "alerts-security",  
"alias": ".alerts-security.alerts-default"  
}  
}  
]  
}

after that created an connector with the below screenshot1.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa938e02c51480fcf504c34b59e900b122eb4072.png)

after that created a rule for windows authentication failure below screenshot attached screenshot2, screenshot3, screenshot4

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/e/feb2c4111d6f9de3c0f47001b67f6c57ae82666a.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/2/82e172ed4f06dbd51586b4c804d5e964ededa416.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af6f1f5da8445bbc121040d177c375f9b65833a0.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/8/68dee89f4a836362e8e989f5df90448e990d7501.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/b/abf013bc7891d7e1a3438cf45746f04c14443c14.png)

But i could not observe any alert on the alert page please find the screenshot attached below

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/7/7757a54edfd5c06e7facedf505f35f6fc0bc84d7.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/796232814a18d4bc82b236d421136e4abd59fd5a.png)

But i can observe the data in the alert index Please find the screenshot attached below

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2a97dabefe68c9464703ef60436d7fda08ebc2cf.png)

I can also query the alert index please find the screenshot attached below

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/a/3aed884980eebde4362c79855f921d099dff448e.png)

requesting support and guidance am i missing something.

Best Regards

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 18, 2023, 5:22am UTC](https://discuss.elastic.co/t/unable-to-observe-security-alerts-in-elastic-security/349502/2 "2023-12-18T05:22:41Z")

</div>

resolved it by creating the rules through detection section.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2024, 5:23am UTC](https://discuss.elastic.co/t/unable-to-observe-security-alerts-in-elastic-security/349502/3 "2024-01-15T05:23:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
