# Custom event category in correlation rule

**URL:** <https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809>\
**Category:** SIEM\
**Created:** [December 16, 2020, 7:19am UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809 "2020-12-16T07:19:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [December 16, 2020, 7:19am UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809/1 "2020-12-16T07:19:20Z")

</div>

Can anyone please explain what does it means

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/05fa6d2880580a39fe495b285f0d923dc299290a.png)

I have Symantec antimalware logs on index pattern logstash-sepm\*. In json document I don't have event.category field but I want to create a correlation rule what if the same malware detects on multiple hosts. So I have to first select a value present in event.category like "process" or anything else. I want to declear field "type" as my event.catoegory but it deoesnot work.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a5f0c4d7e1684819c7a5b8cb533c39a952083e4.png)

Can anyone please explain me how can I define custom event.category here ^

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [December 16, 2020, 12:56pm UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809/2 "2020-12-16T12:56:50Z")

</div>

EQL uses the `@timestamp` and `event.category`  
Yes you can cusotmize fields when running the query using your custom code or from Kibana Dev Console, but from the Kibaba SIEM UI, there is a call to the endpoint :

```auto
POST https://localhost:5601/internal/search/eql
{
  "params": {
    "allow_no_indices": true,
    "index": "my-index",
    "body": {
      "query": ""timestamp_field": "file.accessed" xxxxxx",
      "size": 0
    }
  },
  "options": {
    "ignore": [
      400
    ]
  }
}

```

So you need to have `@timestamp` and `event.category` in your index  
Then use only the content of the query

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [December 17, 2020, 5:45am UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809/3 "2020-12-17T05:45:03Z")

</div>

As far as I could understand from the documentation is, we can define custom field like "event\_category\_field": "file.type" as an event.category if and only if we don't have `event.category` in the json document.

Here I want to ask how can I define `event_category_field` through kibana UI. I know kibana UI objective is to run the EQL syntax only but if I am wanting to declear my custom field as `event.category` how will it be accomplished.

Thank you

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [December 17, 2020, 7:30am UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809/4 "2020-12-17T07:30:19Z")

</div>

Simply you can't from the UI

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [December 17, 2020, 7:48am UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809/5 "2020-12-17T07:48:54Z")

</div>

ok thank you for your reply

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2021, 7:49am UTC](https://discuss.elastic.co/t/custom-event-category-in-correlation-rule/258809/6 "2021-01-14T07:49:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
