Skip to main content
{ Reporting and Compliance / Security Operations }

Elastic Security Detection Posture Report

Delivers a weekly report on Elastic Security data stream gaps, detection rules that are failing, warning, or blind, and anything in the deployment that needs an admin, from offline Elastic Agents to lifecycle errors.

What this agent does

This read-only agent checks the health of an Elastic Security deployment every week. It finds data streams and integrations that stopped receiving documents and Elastic Agents that are offline or unhealthy. It finds detection rules whose last executions failed or warned, rules whose indices or fields are missing, and rules with unfilled execution gaps. It finds machine learning rules whose job or datafeed is not running, and rules that reached the maximum alert limit. It lists prebuilt rules that are disabled or out of date. It summarizes the alerts raised and closed since last week. It flags anything that needs an admin.

The challenge

A detection rule fires only when its documents arrive and its execution completes. An Elastic Agent policy loses an integration and a whole host class stops shipping. An index pattern changes and the rule warns about a missing index on every run. Rules miss their schedule under load and leave gaps nobody sees. The rule list still shows every rule as enabled.

The solution

The agent checks ingestion, agent fleet health, rule execution, and alert activity in one pass each week and compares them with the previous week. It names the data that stopped, the rules that cannot fire, and the fix for each. Provides a weekly briefing a detection engineer can read in a few minutes.

Workflow

  1. 01

    Check ingestion

    Compare the latest document time per data stream and integration with the window, and check Elastic Agent status and lifecycle errors.

  2. 02

    Check rule health

    Read each detection rule's enabled state, last execution status and message, unfilled gaps, machine learning job state, and the indices and fields it depends on.

  3. 03

    Check activity

    Summarize alerts raised, closed, and acknowledged since last week, by rule.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Elastic Security Detection Posture Report

## Measurable outcomes

Every week, the detection engineer knows which data stopped arriving, which detection rules cannot fire, and what needs action before a detection is missed. Track the silent data streams, the unhealthy rules, and the open action items on every run.

## Procedure

Once a week, for the data streams I set, read the latest document time per data stream and per integration. Flag each one with no documents in the last 24 hours, unless I set another window or mark it as expected to be quiet. Compare with the previous week to catch streams that fell silent and streams that are new. Flag Elastic Agents that are offline, unhealthy, or on an outdated version, grouped by agent policy. Flag data streams with index lifecycle errors. For each enabled detection rule, read its last execution status and message, its execution gaps in the window, and the index patterns and fields its query depends on. Flag a rule as blind when a data stream it depends on is silent. Flag rules whose last execution failed or warned, and quote the message, such as a missing index or an unmapped field. Flag every rule with an unfilled gap in the window, with the total gap duration. Flag machine learning rules whose job or datafeed is not running. Flag rules that reached the maximum alert limit in any execution. List rules that were disabled or changed since last week, with who changed them, and prebuilt rules with an available update. Summarize the alerts raised, closed, and acknowledged since the last report, by rule. Flag rules that raised nothing in the last 30 days and at least one in the 90 days before. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Elasticsearch access to the data streams in scope, their lifecycle status, and machine learning jobs and datafeeds, read-only Kibana access to detection rules, their execution results, and alerts, and read-only Fleet access to agents and policies, and nothing more. It never changes rules, agents, policies, data streams, jobs, or alerts.