# Difference between source/destination and server/client

**URL:** <https://discuss.elastic.co/t/difference-between-source-destination-and-server-client/195075>\
**Category:** SIEM\
**Tags:** ecs-elastic-common-schema\
**Created:** [August 13, 2019, 6:11pm UTC](https://discuss.elastic.co/t/difference-between-source-destination-and-server-client/195075 "2019-08-13T18:11:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vbr](https://avatars.discourse-cdn.com/v4/letter/v/8baadc/32.png) [@vbr](https://discuss.elastic.co/u/vbr)\
**Post date:** [August 13, 2019, 6:11pm UTC](https://discuss.elastic.co/t/difference-between-source-destination-and-server-client/195075/1 "2019-08-13T18:11:16Z")

</div>

Hi.  
I'm currently evaluating the SIEM app for integration in our security workflows, and converting most of our datasets to ECS for that purpose. I'm puzzled by the existence of both client/server and source/destination for network connections. The doc says:

```auto
Client / server representations can add semantic context to an exchange, which is helpful to visualize the data in certain situations. 

```

I'm curious in which situations this extra semantic context is meaningful. Are there any cases where the source is not the client or the destination not the server ? Are there any cases where we would have a source/destination but no client/server ?

---

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [August 16, 2019, 1:48pm UTC](https://discuss.elastic.co/t/difference-between-source-destination-and-server-client/195075/2 "2019-08-16T13:48:35Z")

</div>

Hi!

Source and destination should always be filled. This is the baseline we expect to always be present in SIEM.

I'm not sure consumers of ECS such as SIEM are using the client/server pair at this time. But you can add it to your events where you prefer this terminology.

I think there's a few edge cases where only `client` is used, like in APM's RUM events

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2019, 1:56pm UTC](https://discuss.elastic.co/t/difference-between-source-destination-and-server-client/195075/3 "2019-09-13T13:56:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
