# Elastic Security Prebuilt Rules Error

**URL:** <https://discuss.elastic.co/t/elastic-security-prebuilt-rules-error/362135>\
**Category:** Elastic Security\
**Created:** [June 27, 2024, 6:37am UTC](https://discuss.elastic.co/t/elastic-security-prebuilt-rules-error/362135 "2024-06-27T06:37:58Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [June 27, 2024, 1:54pm UTC](https://discuss.elastic.co/t/elastic-security-prebuilt-rules-error/362135/2 "2024-06-27T13:54:01Z")

</div>

Hi @spazzrabbit,

As you've identified, it sounds like your winlogbeat data is missing some required mappings. Since Elastic Security rules [require ECS fields](https://www.elastic.co/guide/en/security/current/siem-field-reference.html), the errors you're seeing are due to those missing mappings.

You mentioned you're using winlogbeat, which should contain these fields by default. Can I ask how you set up winlogbeat?

Most of these mappings come from the associated [index templates](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html) that are created via e.g. `winlogbeat setup`; it seems possible that those templates were not created before winlogbeat was started. [Ingest pipelines](https://www.elastic.co/guide/en/beats/winlogbeat/current/load-ingest-pipelines.html) is another aspect to examine, as those provide much of the winlogbeat data itself.

In general, this looks pretty similar to [No event.category in Winlogbeat](https://discuss.elastic.co/t/no-event-category-in-winlogbeat/343346); I would suggest looking there for ideas as well.

---

_[View the full topic](https://discuss.elastic.co/t/elastic-security-prebuilt-rules-error/362135)._
