# Created field not avail in ML fields

**URL:** <https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [December 2, 2017, 3:23pm UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008 "2017-12-02T15:23:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 2, 2017, 3:23pm UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/1 "2017-12-02T15:23:19Z")

</div>

With alot of help from the discussion board I'm getting closer to this...

I created a field ...

filter {  
if [event\_id] == 4688 and [event\_data][CommandLine] !~ /"(.\*?)"/ {  
mutate {  
add\_field =\> {"event\_data.Suspicious" =\> ""}  
copy =\> {"[event\_data][CommandLine]" =\> "event\_data.Suspicious" }  
}  
}  
}  
... this seemed to automatically make it a keyword.

But the field isn't available in Machine learning

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d26fced323796b3689a44e1b47d8fed725a9734e.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/144cec5b8911bd5f0811790ef5943e0def2ea922.png)

I event tried adding it directly to the JSON for the ML job and that didn't seem to work.

What am I doing wrong now?

---

<div class="post-metadata">

**Author:** ![dmitri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmitri/32/17997_2.png) [@dmitri](https://discuss.elastic.co/u/dmitri)\
**Post date:** [December 4, 2017, 11:02am UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/2 "2017-12-04T11:02:27Z")

</div>

Hi Matt,

Could you use the [get-field-mappings API](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/indices-get-field-mapping.html) to see the mappings of the field you are creating?

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 4, 2017, 4:41pm UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/3 "2017-12-04T16:41:34Z")

</div>

Thanks Dimitris, just when I thought I was sort of getting it...

This seems to work ...

filter {  
if [event\_id] == 4688 and [event\_data][CommandLine] !~ /"(.\*?)"/ {  
mutate {  
copy =\> {"[event\_data][CommandLine]" =\> "[event\_data][Suspicious]" }  
}  
}  
}

and gives me -  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/80ede5e0bde88e5ce907a56c08d281a13a1a138b.png)

and I guess looks ok in the json of the event in Discover -  
"event\_data": {  
"CommandLine": "cmd.exe /c del C:\temp\backdoor.bat",  
"Suspicious": "cmd.exe /c del C:\temp\backdoor.bat",  
},

....but nothing in by\_field\_name for Machine Learning  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c7cba13bc97510cf82bcd979816350c4129ab1d2.png)

---

<div class="post-metadata">

**Author:** ![dmitri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmitri/32/17997_2.png) [@dmitri](https://discuss.elastic.co/u/dmitri)\
**Post date:** [December 4, 2017, 5:01pm UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/4 "2017-12-04T17:01:18Z")

</div>

Could you compare the mappings of `event_data.Suspicious` to something that appears on that list, say `event_data.SubStatus`?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 4, 2017, 5:19pm UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/5 "2017-12-04T17:19:54Z")

</div>

My guess is that the field name is actually just called `Suspicious` and not `event_data.Suspicious`.

Matt can you confirm?

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 4, 2017, 6:09pm UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/6 "2017-12-04T18:09:27Z")

</div>

Not sure,  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2e479068d49749e19acc1f1c5f42b049a2f5f033.png)

and ...

There is one in there... but I think it might be from a previous bungled attempts I made to add/copy the field, I seen to have both in the dev console but NOT available fields in ML -

"winlogbeat-2017.12.01": {  
"mappings": {  
"doc": {  
"Suspicious": {  
"full\_name": "Suspicious",  
"mapping": {  
"Suspicious": {  
"type": "keyword",  
"ignore\_above": 1024  
}  
}  
}  
}  
}  
},

"winlogbeat-2017.12.04": {  
"mappings": {  
"doc": {  
"event\_data.Suspicious": {  
"full\_name": "event\_data.Suspicious",  
"mapping": {  
"Suspicious": {  
"type": "keyword",  
"ignore\_above": 1024  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dmitri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmitri/32/17997_2.png) [@dmitri](https://discuss.elastic.co/u/dmitri)\
**Post date:** [December 5, 2017, 10:41am UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/7 "2017-12-05T10:41:08Z")

</div>

Hi Matt,

I have now confirmed `copy_to` fields are ignored from those drop-downs in the UI. This will be fixed in future release.

As a workaround, you can manually enter the field name in the JSON tab.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2018, 10:41am UTC](https://discuss.elastic.co/t/created-field-not-avail-in-ml-fields/110008/8 "2018-01-02T10:41:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
