# Conflict between ECS and SIEM authentication events visualization

**URL:** <https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936>\
**Category:** SIEM\
**Created:** [January 29, 2020, 2:53am UTC](https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936 "2020-01-29T02:53:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wconnell](https://avatars.discourse-cdn.com/v4/letter/w/f4b2a3/32.png) [@wconnell](https://discuss.elastic.co/u/wconnell)\
**Post date:** [January 29, 2020, 2:53am UTC](https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936/1 "2020-01-29T02:53:43Z")

</div>

On the Host tab of the SIEM app, there's a visualization that counts authentication events using the following logic:

```auto
{
  "aggs": {
    "authentication_success": {
      "filter": {
        "term": {
          "event.type": "authentication_success"
        }
      }
    },
    "authentication_success_histogram": {
      "auto_date_histogram": {
        "field": "@timestamp",
        "buckets": "6"
      },
      "aggs": {
        "count": {
          "filter": {
            "term": {
              "event.type": "authentication_success"
            }
          }
        }
      }
    },
    "authentication_failure": {
      "filter": {
        "term": {
          "event.type": "authentication_failure"
        }
      }
    },
    "authentication_failure_histogram": {
      "auto_date_histogram": {
        "field": "@timestamp",
        "buckets": "6"
      },
      "aggs": {
        "count": {
          "filter": {
            "term": {
              "event.type": "authentication_failure"
            }
          }
        }
      }
    }
  },
  "query": {
    "bool": {
      "filter": [
        {
          "bool": {
            "must": [],
            "filter": [
              {
                "match_all": {}
              }
            ],
            "should": [],
            "must_not": []
          }
        },
        {
          "bool": {
            "filter": [
              {
                "term": {
                  "event.category": "authentication"
                }
              }
            ]
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": 1580093412414,
              "lte": 1580266212415
            }
          }
        }
      ]
    }
  },
  "size": 0,
  "track_total_hits": false
}

```

Notice how the query is looking for event.type to have a value of authentication\_success or authentication\_failure. But per the ECS docs, the only permitted values are access, change, creation, deletion, end, error, info, installation, or start.

What should I set the value for that field to be?

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [January 29, 2020, 12:46pm UTC](https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936/2 "2020-01-29T12:46:38Z")

</div>

Hi Wes,

You are correct - there is a conflict here.  
The logic used to populate the authentication widget in the SIEM app pre-dates the introduction of ECS 1.4 (where the values of ECS field `event.type` are specified), and needs to be updated.

As of ECS 1.4, the ECS-compatible mapping of authentication events will now require three categorization fields, for example:  
`event.category:"authentication"` (no change)  
`event.type:"start"`  
`event.outcome:"failure"`

We're planning to update the SIEM app in a future release to handle the ECS 1.4 implementation, so I'd recommend following the ECS spec.

Thanks for bringing this up.

---

<div class="post-metadata">

**Author:** ![wconnell](https://avatars.discourse-cdn.com/v4/letter/w/f4b2a3/32.png) [@wconnell](https://discuss.elastic.co/u/wconnell)\
**Post date:** [January 29, 2020, 7:16pm UTC](https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936/3 "2020-01-29T19:16:31Z")

</div>

Good to know - thanks so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2020, 7:16pm UTC](https://discuss.elastic.co/t/conflict-between-ecs-and-siem-authentication-events-visualization/216936/4 "2020-02-26T19:16:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
