# What is External Alerts Detection Rule?

**URL:** <https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817>\
**Category:** Elastic Security\
**Created:** [October 17, 2022, 5:09pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817 "2022-10-17T17:09:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [October 17, 2022, 5:09pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817/1 "2022-10-17T17:09:59Z")

</div>

Hello, what exactly is "External Alerts" in the SIEM rules? It doesn't do anything for us.

---

<div class="post-metadata">

**Author:** ![WinterKnight](https://avatars.discourse-cdn.com/v4/letter/w/50afbb/32.png) [@WinterKnight](https://discuss.elastic.co/u/WinterKnight)\
**Post date:** [October 17, 2022, 8:26pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817/2 "2022-10-17T20:26:53Z")

</div>

For us it's any other alert triggered by another security tool like Palo Alto. I get a ton of URL\_Filtering alerts from my Palo's marked as External Alerts.

---

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [October 17, 2022, 10:03pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817/3 "2022-10-17T22:03:17Z")

</div>

I wish it would just be a default action rule, because I need to set the email alert action for every rule that we activated... over 500 rules and need to set the email alert one by one. My hope was "External Alerts" would apply to all alerts not from the Elastic Security rule.

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [November 13, 2022, 1:39pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817/4 "2022-11-13T13:39:08Z")

</div>

Have you ever thought about the possibility that configuring all this amount of email alerts can lead to many false positives and wear on the triage of events?

In fact, external alerts are alerts produced by tools such as IPS rules in a fortigate, DLP rules in office 365, Elastic endpoint alerts, among others.

> [@lamp123432](#):
>
> I wish it would just be a default action rule, because I need to set the email alert action for every rule that we activated... over 500 rules and need to set the email alert one by one. My hope was "External Alerts" would apply to all alerts not from the Elastic Security rule.

---

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [December 5, 2022, 1:53pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817/5 "2022-12-05T13:53:19Z")

</div>

That's the point of a SIEM, we receive tons of false positives, look at them, then tuned them accordingly - every network/environment is different. After a month, things are quieter, and when there's an alert, it becomes closer to be a true positive.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2023, 1:53pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817/6 "2023-01-02T13:53:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
