Loading

Troubleshoot detection rules

This topic covers common troubleshooting issues when creating or managing detection rules.

Depending on your privileges and whether detection system indices have already been created for the Kibana space, you might get one of these error messages when you open the Alerts or Rules page:

When a rule fails to run close to its scheduled time, some alerts may be missing. There are a number of ways to try to resolve this issue.

You can also use Task Manager in Kibana to troubleshoot background tasks and processes that may be related to missing alerts: