# Verification\_exception Error during Rule Execution

**URL:** <https://discuss.elastic.co/t/verification-exception-error-during-rule-execution/275781>\
**Category:** Elastic Security\
**Created:** [June 14, 2021, 2:47am UTC](https://discuss.elastic.co/t/verification-exception-error-during-rule-execution/275781 "2021-06-14T02:47:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [June 14, 2021, 2:47am UTC](https://discuss.elastic.co/t/verification-exception-error-during-rule-execution/275781/1 "2021-06-14T02:47:08Z")

</div>

Hi there,

I am facing a particular error regarding many pre-built Elastic rules. Once they were activated, many of them start failing when executing - with the error: `An error occurred during rule execution: message: "verification_exception"`.

Some of these rules include:

- Suspicious .NET Code Compilation
- Suspicious WMI Image Load from MS Office
- NTDS or SAM Database File Copied
- Lateral Movement via Startup Folder

It appears that these rules' queries are written in EQL, and that they typically have 3 index patterns: `winlogbeat-*`, `logs-endpoint.events.*`, and `logs-windows.*`. I have only got Winlogbeat in my case, without Elastic Agents/Endpoints running.

Must I have all 3 of the index patterns present in order for these rules to execute successfully?

For reference, a slight variation of this issue is found in [this GitHub issue](https://github.com/elastic/kibana/issues/89960).

---

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [July 6, 2021, 5:37am UTC](https://discuss.elastic.co/t/verification-exception-error-during-rule-execution/275781/2 "2021-07-06T05:37:22Z")

</div>

Bump!

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [July 16, 2021, 5:57pm UTC](https://discuss.elastic.co/t/verification-exception-error-during-rule-execution/275781/3 "2021-07-16T17:57:23Z")

</div>

Hi there,

Usually that error means you do not have valid EQL because of a missing data driven value.

For example in dev tools if you do something like this:

```json
POST /auditbeat-*/_eql/search
{
  "query": "sequence by blah.name [any where true] [any where true]"
}

```

You get this error back:

```json
{
  "error" : {
    "root_cause" : [
      {
        "type" : "verification_exception",
        "reason" : "Found 1 problem\nline 1:13: Unknown column [blah.name], did you mean any of [vlan.name, dll.name, file.name, geo.name, host.name, os.name, rule.name, user.name, agent.name, group.name, package.name]?"
      }
    ],
    "type" : "verification_exception",
    "reason" : "Found 1 problem\nline 1:13: Unknown column [blah.name], did you mean any of [vlan.name, dll.name, file.name, geo.name, host.name, os.name, rule.name, user.name, agent.name, group.name, package.name]?"
  },
  "status" : 400
}

```

I would if possible take your query and set of indices and play with them in the dev tooling to see if you can get the reason back if you're not in another part of the UI. Should help you sleuth it out.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [July 16, 2021, 6:02pm UTC](https://discuss.elastic.co/t/verification-exception-error-during-rule-execution/275781/4 "2021-07-16T18:02:43Z")

</div>

You should be able to see the same validation by clicking in the UI as well:

 ![Screen Shot 2021-07-16 at 12.01.50 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73fc833a9ce54d60e1c02cf2f76bcbb451245eab.png)

If you're making a detection engine rule which should show the same type of errors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2021, 6:03pm UTC](https://discuss.elastic.co/t/verification-exception-error-during-rule-execution/275781/5 "2021-08-13T18:03:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
