# \#detection-rules

**URL:** https://discuss.elastic.co/tag/detection-rules/64.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Creating observability rules - cases](https://discuss.elastic.co/t/creating-observability-rules-cases/387478)

<div class="topic-metadata">

**Author:** [@reports](https://discuss.elastic.co/u/reports)\
**Replies:** 2\
**Last updated:** [July 6, 2026, 8:53am UTC](https://discuss.elastic.co/t/creating-observability-rules-cases/387478 "2026-07-06T08:53:17Z")

</div>

I have created Observability rules in Kibana and integrated the Cases action to enable auto-generated cases. Initially, I faced a limitation where I couldn't customize the case payload to extract critical alert details. …

---

## [Indicator Match rule not generating alerts (Basic license, self-managed 9.3.0)](https://discuss.elastic.co/t/indicator-match-rule-not-generating-alerts-basic-license-self-managed-9-3-0/385726)

<div class="topic-metadata">

**Author:** [@arav](https://discuss.elastic.co/u/arav)\
**Replies:** 1\
**Last updated:** [April 16, 2026, 7:27pm UTC](https://discuss.elastic.co/t/indicator-match-rule-not-generating-alerts-basic-license-self-managed-9-3-0/385726 "2026-04-16T19:27:09Z")

</div>

Hi all, I am running a self-managed Elastic Stack (v9.3.0) with a Basic license. I have ingested threat intelligence data from MISP using the official integration, and I am trying to create an Indicator Match rule in E…

---

## [Clarification on using "timestamp\_override: event.ingested" with EQL sequence rules](https://discuss.elastic.co/t/clarification-on-using-timestamp-override-event-ingested-with-eql-sequence-rules/385377)

<div class="topic-metadata">

**Author:** [@iremtoru](https://discuss.elastic.co/u/iremtoru)\
**Replies:** 0\
**Last updated:** [March 9, 2026, 11:22am UTC](https://discuss.elastic.co/t/clarification-on-using-timestamp-override-event-ingested-with-eql-sequence-rules/385377 "2026-03-09T11:22:02Z")

</div>

Hello, I’m looking for clarification and guidance around the use of timestamp\_override: event.ingested in EQL sequence rules. From my understanding and search of official docs: timestamp\_override: event.ingested is …

---

## [Elastic rule Hyperlinks in Highlighted Fields](https://discuss.elastic.co/t/elastic-rule-hyperlinks-in-highlighted-fields/384894)

<div class="topic-metadata">

**Author:** [@welch27330](https://discuss.elastic.co/u/welch27330)\
**Replies:** 2\
**Last updated:** [February 13, 2026, 2:48am UTC](https://discuss.elastic.co/t/elastic-rule-hyperlinks-in-highlighted-fields/384894 "2026-02-13T02:48:48Z")

</div>

Is it possible to create a custom clickable hyperlink in the highlighted fields. The link could be constructed in several ways but generally constructed from data that is present in the alert it self. The reason for thi…

---

## [Kibana rule for detecting lost applicattions](https://discuss.elastic.co/t/kibana-rule-for-detecting-lost-applicattions/383475)

<div class="topic-metadata">

**Author:** [@juanmgarciaf](https://discuss.elastic.co/u/juanmgarciaf)\
**Replies:** 2\
**Last updated:** [November 18, 2025, 10:50am UTC](https://discuss.elastic.co/t/kibana-rule-for-detecting-lost-applicattions/383475 "2025-11-18T10:50:34Z")

</div>

Hello, I'm trying to create a rule in Kibana (v 8.18.7) to detect when an application has suddenly stop to inject documents in Kibana. My idea is to create a Kibana rule for that (without use transforms and Machine Lear…

---

## [Detection rules manual run: cannot be scheduled earlier than 90 days ago](https://discuss.elastic.co/t/detection-rules-manual-run-cannot-be-scheduled-earlier-than-90-days-ago/383033)

<div class="topic-metadata">

**Author:** [@niklaskurvinen](https://discuss.elastic.co/u/niklaskurvinen)\
**Replies:** 2\
**Last updated:** [October 31, 2025, 4:33am UTC](https://discuss.elastic.co/t/detection-rules-manual-run-cannot-be-scheduled-earlier-than-90-days-ago/383033 "2025-10-31T04:33:00Z")

</div>

Hi, Just came across the “Manual rule run cannot be scheduled earlier than 90 days ago” message for the first time. Is there a reason for this limitation and more importantly; can I override it? Tried to find any kind o…

---

## [Rule Scope field does not appear while editing Custom threshold rule](https://discuss.elastic.co/t/rule-scope-field-does-not-appear-while-editing-custom-threshold-rule/382864)

<div class="topic-metadata">

**Author:** [@marcelpineda](https://discuss.elastic.co/u/marcelpineda)\
**Replies:** 2\
**Last updated:** [October 27, 2025, 5:26pm UTC](https://discuss.elastic.co/t/rule-scope-field-does-not-appear-while-editing-custom-threshold-rule/382864 "2025-10-27T17:26:06Z")

</div>

I have an Elastic Instance running v8.18.0. When I go to Observability \> Alerts, then click ‘Manage Rules’ \> Create Rule and start creating a Custom Threshold rule, I see this option: After saving the rule and editin…

---

## [Creation of rule](https://discuss.elastic.co/t/creation-of-rule/379285)

<div class="topic-metadata">

**Author:** [@madhavsankarg](https://discuss.elastic.co/u/madhavsankarg)\
**Replies:** 3\
**Last updated:** [June 19, 2025, 9:43am UTC](https://discuss.elastic.co/t/creation-of-rule/379285 "2025-06-19T09:43:04Z")

</div>

HI Everyone, I was trying to create a rule using Elasticsearch Query with KQL. In the step while trying to select the Data View I am not able to select other ones which is available and cant even see the list of availab…

---

## [How to include a field value in message body in Rules and Connectors?](https://discuss.elastic.co/t/how-to-include-a-field-value-in-message-body-in-rules-and-connectors/379126)

<div class="topic-metadata">

**Author:** [@Dariia\_Hrebenichenko](https://discuss.elastic.co/u/Dariia_Hrebenichenko)\
**Replies:** 1\
**Last updated:** [June 12, 2025, 10:59am UTC](https://discuss.elastic.co/t/how-to-include-a-field-value-in-message-body-in-rules-and-connectors/379126 "2025-06-12T10:59:39Z")

</div>

Hello there! I'm working on an alerting system. I use Kibana connector log and Logstash to sand emails. For now I have rule to show just a count of files, but I want to include only specific fields in the message body…

---

## [Detection Rules (SIEM) exceptions bug?](https://discuss.elastic.co/t/detection-rules-siem-exceptions-bug/378531)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 2\
**Last updated:** [May 28, 2025, 6:18am UTC](https://discuss.elastic.co/t/detection-rules-siem-exceptions-bug/378531 "2025-05-28T06:18:22Z")

</div>

Hello, Everytime I try to create an exception for builtin security rule "Enumeration of Kernel Modules" I receive an error : type: Invalid literal value, expected "new\_terms", language: Invalid enum value. Expected 'ku…

---

## [I'm experiencing an issue with rule configuration in Stack Management](https://discuss.elastic.co/t/im-experiencing-an-issue-with-rule-configuration-in-stack-management/378343)

<div class="topic-metadata">

**Author:** [@elastic\_interogation](https://discuss.elastic.co/u/elastic_interogation)\
**Replies:** 4\
**Last updated:** [May 21, 2025, 8:47am UTC](https://discuss.elastic.co/t/im-experiencing-an-issue-with-rule-configuration-in-stack-management/378343 "2025-05-21T08:47:45Z")

</div>

Hi, I would like some help in the Rules and Connectors folder, I created rules based on an Elasticsearch query to detect the number of matches, using a custom threshold that I want to set myself. However, I don't unde…

---

## [Anybody successfully created a detection rule for Red Hat security updates](https://discuss.elastic.co/t/anybody-successfully-created-a-detection-rule-for-red-hat-security-updates/377446)

<div class="topic-metadata">

**Author:** [@taprove](https://discuss.elastic.co/u/taprove)\
**Replies:** 1\
**Last updated:** [May 9, 2025, 10:58am UTC](https://discuss.elastic.co/t/anybody-successfully-created-a-detection-rule-for-red-hat-security-updates/377446 "2025-05-09T10:58:02Z")

</div>

I read that is is possible to create a detection rule to alert if there are security updates required on a Red Hat or CentOS box (we use RHEL for production, CentOS for testing). I came across the following "query" but …

---

## [Custom Threshold not triggering alert to index](https://discuss.elastic.co/t/custom-threshold-not-triggering-alert-to-index/377531)

<div class="topic-metadata">

**Author:** [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)\
**Replies:** 1\
**Last updated:** [April 30, 2025, 1:00pm UTC](https://discuss.elastic.co/t/custom-threshold-not-triggering-alert-to-index/377531 "2025-04-30T13:00:34Z")

</div>

I tried to create a rule using custom threshold to write to an index for the alert action. Running 8.13. I created the index, and mappings ahead of time I added the connector + the index I tested the rule by going bel…

---

## [Multiple threat frameworks in a single rule](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533)

<div class="topic-metadata">

**Author:** [@nahuel978](https://discuss.elastic.co/u/nahuel978)\
**Replies:** 3\
**Last updated:** [April 28, 2025, 2:55am UTC](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533 "2025-04-28T02:55:41Z")

</div>

I'm interested in knowing if any Elastic detection rules use two different threat frameworks within the same rule. According to the ECS documentation: The threat.framework field is defined as a keyword, which suggests…

---

## [Prebuilt Rule Customization is an Enterprise feature?!](https://discuss.elastic.co/t/prebuilt-rule-customization-is-an-enterprise-feature/377312)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 0\
**Last updated:** [April 19, 2025, 4:14pm UTC](https://discuss.elastic.co/t/prebuilt-rule-customization-is-an-enterprise-feature/377312 "2025-04-19T16:14:46Z")

</div>

Hey, I was excited to read about prebuilt rule customization, which would alleviate my pain of duplicating prebuilt rules just to add some minute detail. However, I was shocked to see this not just not in the free vers…

---

## [Share rules and Connectors to other spaces as well their related objects](https://discuss.elastic.co/t/share-rules-and-connectors-to-other-spaces-as-well-their-related-objects/375439)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [March 5, 2025, 9:22am UTC](https://discuss.elastic.co/t/share-rules-and-connectors-to-other-spaces-as-well-their-related-objects/375439 "2025-03-05T09:22:24Z")

</div>

Any way to Share Rules and Connector to other spaces as well (Rules , and related object to other spaces ) As we have mutilple spaces for our app teams and developers and others. we want to share the connectors and ale…

---

## [How does the look-back time of detection rules work?](https://discuss.elastic.co/t/how-does-the-look-back-time-of-detection-rules-work/374118)

<div class="topic-metadata">

**Author:** [@pok\_lehbim](https://discuss.elastic.co/u/pok_lehbim)\
**Replies:** 1\
**Last updated:** [February 5, 2025, 12:48pm UTC](https://discuss.elastic.co/t/how-does-the-look-back-time-of-detection-rules-work/374118 "2025-02-05T12:48:56Z")

</div>

What time period do rules look over when they are ran (automatically)? Is that defined by the look-back time we set? If that's the case, I've come across some odd behavior from a custom threshold rule (grouped by 3 occu…

---

## [How do I use Exceptions\_list and Alert\_Suppressions schemas for detections in TOML format?](https://discuss.elastic.co/t/how-do-i-use-exceptions-list-and-alert-suppressions-schemas-for-detections-in-toml-format/374036)

<div class="topic-metadata">

**Author:** [@obsidian](https://discuss.elastic.co/u/obsidian)\
**Replies:** 0\
**Last updated:** [February 3, 2025, 11:42pm UTC](https://discuss.elastic.co/t/how-do-i-use-exceptions-list-and-alert-suppressions-schemas-for-detections-in-toml-format/374036 "2025-02-03T23:42:49Z")

</div>

Per the detection rules API documentation and elastic detection rules repo, I am unable to find examples of how to use these objects in TOML format. How would these schema's look in TOML? My detections show up in elastic…

---

## [Elastic Agent config requirements for "Hosts File Modified" rule](https://discuss.elastic.co/t/elastic-agent-config-requirements-for-hosts-file-modified-rule/373854)

<div class="topic-metadata">

**Author:** [@justin2](https://discuss.elastic.co/u/justin2)\
**Replies:** 0\
**Last updated:** [January 29, 2025, 5:53pm UTC](https://discuss.elastic.co/t/elastic-agent-config-requirements-for-hosts-file-modified-rule/373854 "2025-01-29T17:53:18Z")

</div>

Hello, I'm testing how some Elastic Security rules work with Beats versus Agents. I was curious about the integration requirements for the "Hosts File Modified" rule (link). Per the setup section for the "Hosts File Mo…

---

## [Create Cases with Elastic Security Rule Alerts](https://discuss.elastic.co/t/create-cases-with-elastic-security-rule-alerts/373067)

<div class="topic-metadata">

**Author:** [@logalicious](https://discuss.elastic.co/u/logalicious)\
**Replies:** 2\
**Last updated:** [January 27, 2025, 1:14pm UTC](https://discuss.elastic.co/t/create-cases-with-elastic-security-rule-alerts/373067 "2025-01-27T13:14:19Z")

</div>

Is there a way to create cases automatically when specific Security Rules trigger? I see lots of integrations for third-party case management tools, but I do not see any way to integrate security rules with Elastic Cases…

---

## [Elasticsearch Shared Exception Lists](https://discuss.elastic.co/t/elasticsearch-shared-exception-lists/373456)

<div class="topic-metadata">

**Author:** [@iremtoru](https://discuss.elastic.co/u/iremtoru)\
**Replies:** 2\
**Last updated:** [January 23, 2025, 2:22pm UTC](https://discuss.elastic.co/t/elasticsearch-shared-exception-lists/373456 "2025-01-23T14:22:06Z")

</div>

Hello, I created some shared exception lists for some known and legit bots used in user agents and associated it with some of my detection rules but when I checked the results I am still seeing the them. I found the do…

---

## [SIEM detection rule](https://discuss.elastic.co/t/siem-detection-rule/372978)

<div class="topic-metadata">

**Author:** [@aravindraja](https://discuss.elastic.co/u/aravindraja)\
**Replies:** 1\
**Last updated:** [January 9, 2025, 4:42pm UTC](https://discuss.elastic.co/t/siem-detection-rule/372978 "2025-01-09T16:42:27Z")

</div>

Hi Folks, Enabling all the SIEM detection rules will consume resource at agent end? And also, is it a best practice to enable all the prebuilt SIEM detection rules? Thanks in advance

---

## [Cannot read properties of undefined (reading ‘statusCode’) when trying to create an Elasticsearch query rule](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-statuscode-when-trying-to-create-an-elasticsearch-query-rule/370061)

<div class="topic-metadata">

**Author:** [@x271091-bce\_sangroup](https://discuss.elastic.co/u/x271091-bce_sangroup)\
**Replies:** 0\
**Last updated:** [November 5, 2024, 10:00am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-statuscode-when-trying-to-create-an-elasticsearch-query-rule/370061 "2024-11-05T10:00:58Z")

</div>

When I open the Elasticsearch query rule menu, I keep getting the same error: \*\*Error fetching fields for data view log-prep-\* (ID: 93f9403b-5153-5e38-a9ab-035d84a55566).\*\* Cannot read undefined properties (reading ‘st…

---

## [Rule Recovery Functionality](https://discuss.elastic.co/t/rule-recovery-functionality/369771)

<div class="topic-metadata">

**Author:** [@jeffabar](https://discuss.elastic.co/u/jeffabar)\
**Replies:** 0\
**Last updated:** [October 29, 2024, 10:55pm UTC](https://discuss.elastic.co/t/rule-recovery-functionality/369771 "2024-10-29T22:55:23Z")

</div>

I have a DSL query which finds the latest record grouped by a field Module and if that latest record has another field unexpected\_state set to true it matches. I have the rule set for "FOR THE LAST 5 minutes" and it run…

---

## [Detection Rules Update Failure](https://discuss.elastic.co/t/detection-rules-update-failure/369051)

<div class="topic-metadata">

**Author:** [@syk](https://discuss.elastic.co/u/syk)\
**Replies:** 8\
**Last updated:** [October 22, 2024, 1:42pm UTC](https://discuss.elastic.co/t/detection-rules-update-failure/369051 "2024-10-22T13:42:05Z")

</div>

Hi, With version 8.15.3 we see 18 prebuilt security detection rules failing to update (Screenshot): List of rules not being able to update: Anomalous Windows Process Creation Suspicious Windows Process Cluster Spawn…

---

## [I can't add or edit Shared Exception List](https://discuss.elastic.co/t/i-cant-add-or-edit-shared-exception-list/367063)

<div class="topic-metadata">

**Author:** [@Matheus\_Marques](https://discuss.elastic.co/u/Matheus_Marques)\
**Replies:** 1\
**Last updated:** [October 2, 2024, 11:19am UTC](https://discuss.elastic.co/t/i-cant-add-or-edit-shared-exception-list/367063 "2024-10-02T11:19:58Z")

</div>

I'm facing problem to edit my shared exception list... I'd like to edit my rules to add a new SHA256 hash for a new version of my .exe, but this field is locked. How to solve it?

---

## [Is this even Possible?](https://discuss.elastic.co/t/is-this-even-possible/367256)

<div class="topic-metadata">

**Author:** [@Gisselle-Guzman](https://discuss.elastic.co/u/Gisselle-Guzman)\
**Replies:** 1\
**Last updated:** [September 30, 2024, 8:17pm UTC](https://discuss.elastic.co/t/is-this-even-possible/367256 "2024-09-30T20:17:29Z")

</div>

Hi all ! I have been a pentester but now I'm working on the blue side of things. So anyways I know all the malicious commands, the programs, and what an attacker will type, say into powershell or into their attack machin…

---

## [Adding a custom field in alerts](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [September 11, 2024, 1:54pm UTC](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216 "2024-09-11T13:54:53Z")

</div>

Hello team, I am trying to create new rule in kibana for cpu utilization is more than 80 %. I am monitoring 3 host in my community version of Kibana. When it meet threshold criteare i am creating index and data is gett…

---

## [Question Regarding OpenSource License Change for Detection Rules Repository](https://discuss.elastic.co/t/question-regarding-opensource-license-change-for-detection-rules-repository/365965)

<div class="topic-metadata">

**Author:** [@JcabreraC](https://discuss.elastic.co/u/JcabreraC)\
**Replies:** 0\
**Last updated:** [September 3, 2024, 1:58pm UTC](https://discuss.elastic.co/t/question-regarding-opensource-license-change-for-detection-rules-repository/365965 "2024-09-03T13:58:30Z")

</div>

Hello, Based on your recent blog post (link), I have a question: Will the OpenSource license change also apply to repositories like detection-rules? If so, do you have a timeline for when this change will take place? …

---

## [Increasing number of Alerts for Detection Rules](https://discuss.elastic.co/t/increasing-number-of-alerts-for-detection-rules/357064)

<div class="topic-metadata">

**Author:** [@uhxqc](https://discuss.elastic.co/u/uhxqc)\
**Replies:** 17\
**Last updated:** [June 12, 2024, 1:14am UTC](https://discuss.elastic.co/t/increasing-number-of-alerts-for-detection-rules/357064 "2024-06-12T01:14:38Z")

</div>

Hello, I am currently using the open source version of Elastic. I have created a couple of Detection Rules. But the number of alerts I can create per rule is limited to 100. If my understanding is correct, the number o…

[Next page](https://discuss.elastic.co/tag/detection-rules/64.md?match_all_tags=true&page=1&tags%5B%5D=detection-rules)
