diff --git a/x-pack/plugins/security_solution/server/lib/detection_engine/signals/signal_rule_alert_type.ts b/x-pack/plugins/security_solution/server/lib/detection_engine/signals/signal_rule_alert_type.ts index 4eda9150e52f101..fc29c33875309de 100644 --- a/x-pack/plugins/security_solution/server/lib/detection_engine/signals/signal_rule_alert_type.ts +++ b/x-pack/plugins/security_solution/server/lib/detection_engine/signals/signal_rule_alert_type.ts @@ -450,6 +450,7 @@ export const signalRulesAlertType = ({ buildRuleMessage, }); } else if (isEqlRule(type)) { + // TODO: Sync. Seems like severity and risk score overrides are not taken into account during processing EQL rules. if (query === undefined) { throw new Error('EQL query rule must have a query defined'); }