# EQL syntax error?

**URL:** <https://discuss.elastic.co/t/eql-syntax-error/277301>\
**Category:** Elastic Security\
**Tags:** eql-elastic-query-language\
**Created:** [June 29, 2021, 7:16am UTC](https://discuss.elastic.co/t/eql-syntax-error/277301 "2021-06-29T07:16:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [June 29, 2021, 7:16am UTC](https://discuss.elastic.co/t/eql-syntax-error/277301/1 "2021-06-29T07:16:05Z")

</div>

I'm trying to inspect the results of an EQL query (based on the built-in hosts modification rule). However when I run the EQL query :

```auto
    file where event.type in ("change", "creation") and
      file.path : ("/private/etc/hosts", "/etc/hosts", "?:\\Windows\\System32\\drivers\\etc\\hosts") 

```

I get an error : "verification\_exception: Found 1 problem line 2:7: Unknown column [file.path], did you mean any of [log.file.path, dll.path, url.path, osquery.path, package.path]?"

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [June 29, 2021, 6:20pm UTC](https://discuss.elastic.co/t/eql-syntax-error/277301/2 "2021-06-29T18:20:04Z")

</div>

The EQL query looks at the mappings in the index patterns to determine what fields are available.  
It looks like none of the index patterns that were searched contain `file.path` in the mapping. Sounds like your data that you currently have doesn't populate this field

---

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [June 29, 2021, 11:53pm UTC](https://discuss.elastic.co/t/eql-syntax-error/277301/3 "2021-06-29T23:53:56Z")

</div>

This index / mapping is created by elastic-agent in security solution. Additionally the EQL is a built-in rule provided by Elastic so there should be no mismatch here.

Thirdly this EQL query has already run and matched events as I have 150 matches and hence I'm trying to manually run the query to figure out what is going on - does that make sense?

Hilton

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [June 30, 2021, 4:30pm UTC](https://discuss.elastic.co/t/eql-syntax-error/277301/4 "2021-06-30T16:30:01Z")

</div>

The indexes that the rule checks are `index = ["auditbeat-*", "winlogbeat-*", "logs-endpoint.events.*", "logs-windows.*"]`. You can search those mappings for `file.path` by running this in Dev Tools in Kibana:

```auto
GET auditbeat-*,winlogbeat-*,logs-endpoint.events.*,logs-windows.*/_mapping/field/file.path

```

This is the output I'm getting on my stack when I run this. Note that this will depend on what integrations you have and what indexes they've created. If you're using Elastic Endpoint, you can expect `.ds-logs-endpoint.events.file-default-*` to exist, which is the backing index for the data stream `logs-endpoint.events.file-default-*`.

```json
{
  ".ds-logs-endpoint.events.process-default-2021.06.10-000001" : {
    "mappings" : { }
  },
  ".ds-logs-endpoint.events.file-default-2021.06.10-000001" : {
    "mappings" : {
      "file.path" : {
        "full_name" : "file.path",
        "mapping" : {
          "path" : {
            "type" : "keyword",
            "ignore_above" : 1024,
            "fields" : {
              "caseless" : {
                "type" : "keyword",
                "ignore_above" : 1024,
                "normalizer" : "lowercase"
              },
              "text" : {
                "type" : "text"
              }
            }
          }
        }
      }
    }
  },
  "auditbeat-7.8.0" : {
    "mappings" : { }
  },
  ".ds-logs-endpoint.events.network-default-2021.06.10-000001" : {
    "mappings" : { }
  },
  ".ds-logs-endpoint.events.library-default-2021.06.10-000001" : {
    "mappings" : {
      "file.path" : {
        "full_name" : "file.path",
        "mapping" : {
          "path" : {
            "type" : "keyword",
            "ignore_above" : 1024,
            "fields" : {
              "caseless" : {
                "type" : "keyword",
                "ignore_above" : 1024,
                "normalizer" : "lowercase"
              },
              "text" : {
                "type" : "text"
              }
            }
          }
        }
      }
    }
  },
  ".ds-logs-endpoint.events.registry-default-2021.06.10-000001" : {
    "mappings" : { }
  },
  "auditbeat-7.13.2-2021.06.22-000001" : {
    "mappings" : {
      "file.path" : {
        "full_name" : "file.path",
        "mapping" : {
          "path" : {
            "type" : "keyword",
            "ignore_above" : 1024,
            "fields" : {
              "text" : {
                "type" : "text",
                "norms" : false
              }
            }
          }
        }
      }
    }
  },
  ".ds-logs-endpoint.events.security-default-2021.06.10-000001" : {
    "mappings" : { }
  },
  "auditbeat-7.14.0-2021.06.09-000001" : {
    "mappings" : {
      "file.path" : {
        "full_name" : "file.path",
        "mapping" : {
          "path" : {
            "type" : "keyword",
            "ignore_above" : 1024,
            "fields" : {
              "text" : {
                "type" : "text",
                "norms" : false
              }
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 4:30pm UTC](https://discuss.elastic.co/t/eql-syntax-error/277301/5 "2021-07-28T16:30:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
