<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configured Detections Have Disappeared from All Automation Rules in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Configured-Detections-Have-Disappeared-from-All-Automation-Rules/m-p/761596#M12937</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I'm experiencing an issue with Automation Rules in Splunk Enterprise Security (8.5.1). Sometimes I'm able to add a detection successfully, but after saving, other previously configured detections disappear. In other cases, I receive the following error:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"Could not update automation rule: Failed to create automation rule mapping as detection is already mapped to an automation rule."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What's confusing is that after this happens, some of the detections I had added previously are no longer visible in the rule. The behavior seems inconsistent, as sometimes detections can be added and other times they disappear or trigger the error above.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2026 14:23:09 GMT</pubDate>
    <dc:creator>shenglc</dc:creator>
    <dc:date>2026-06-11T14:23:09Z</dc:date>
    <item>
      <title>Configured Detections Have Disappeared from All Automation Rules</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Configured-Detections-Have-Disappeared-from-All-Automation-Rules/m-p/761596#M12937</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I'm experiencing an issue with Automation Rules in Splunk Enterprise Security (8.5.1). Sometimes I'm able to add a detection successfully, but after saving, other previously configured detections disappear. In other cases, I receive the following error:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"Could not update automation rule: Failed to create automation rule mapping as detection is already mapped to an automation rule."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What's confusing is that after this happens, some of the detections I had added previously are no longer visible in the rule. The behavior seems inconsistent, as sometimes detections can be added and other times they disappear or trigger the error above.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 14:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Configured-Detections-Have-Disappeared-from-All-Automation-Rules/m-p/761596#M12937</guid>
      <dc:creator>shenglc</dc:creator>
      <dc:date>2026-06-11T14:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Configured Detections Have Disappeared from All Automation Rules</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Configured-Detections-Have-Disappeared-from-All-Automation-Rules/m-p/761742#M12939</link>
      <description>&lt;P&gt;Hey shenglc — there are two things tangled together here: one is expected behavior, the other looks like a bug.&lt;/P&gt;&lt;P&gt;The error first. In ES 8.x a detection can only be mapped to one automation rule at a time — On or Off doesn't matter. So "Failed to create automation rule mapping as detection is already mapped to an automation rule" means that detection is already attached to another rule (or a stale mapping for it exists). To move it, remove it from the rule that currently owns it, save, then add it to the new one. Quick way to find where it lives: open the detection itself (Edit event-based / finding-based detection) — the Details section names the automation rule it's tied to.&lt;/P&gt;&lt;P&gt;A second thing that can make detections "vanish": every detection in a rule has to be status = On. If detection versioning is on and a save spins up a new version that isn't enabled (new versions don't auto-turn-on), or a detection otherwise flips off, it drops out of the rule's valid set. Worth confirming all your mapped detections are still On and you're not looking at a superseded, disabled version.&lt;/P&gt;&lt;P&gt;Now the part that isn't expected: previously-saved detections disappearing when you add a new one. The 8.5 UI is supposed to gray out detections already used elsewhere so you can't even pick them — so hitting the "already mapped" error &lt;EM&gt;and&lt;/EM&gt; losing other detections on save looks like the mapping save is partially failing and rewriting the rule with a subset instead of cleanly rejecting just the conflicting detection. That's not something you can config around.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Practically:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Edit one detection at a time, save, then re-open the rule to confirm the list actually persisted before adding the next. Avoid two tabs or two admins editing at once.&lt;/LI&gt;&lt;LI&gt;Before adding any detection, check its detail page to confirm it isn't already mapped elsewhere, and remove it there first if it is.&lt;/LI&gt;&lt;LI&gt;If a detection shows as "already mapped" but you can't find which rule owns it, that's an orphaned mapping — Support needs to clean that one up.&lt;/LI&gt;&lt;LI&gt;Check the 8.5.x release notes and known issues, and since this reproduces, open a Splunk Support case with exact repro steps. There have already been automation-rule regressions reported across the 8.x upgrades, so it's worth putting in front of them directly.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Doc:&lt;/STRONG&gt; &lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.5/automation-with-playbooks/configure-automation-rules-to-run-playbooks-based-on-findings-in-splunk-enterprise-security" target="_blank"&gt;Configure automation rules (ES 8.5)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Couple things to narrow it down: are the detections that disappear ones you'd also added (or tried to add) to a different rule, and do you have detection versioning turned on?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 03:49:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Configured-Detections-Have-Disappeared-from-All-Automation-Rules/m-p/761742#M12939</guid>
      <dc:creator>natecrisler</dc:creator>
      <dc:date>2026-06-18T03:49:08Z</dc:date>
    </item>
  </channel>
</rss>

