# Event.type field in system module logs not ECS compliant

**URL:** <https://discuss.elastic.co/t/event-type-field-in-system-module-logs-not-ecs-compliant/333579>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 16, 2023, 1:59pm UTC](https://discuss.elastic.co/t/event-type-field-in-system-module-logs-not-ecs-compliant/333579 "2023-05-16T13:59:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lorygold](https://avatars.discourse-cdn.com/v4/letter/l/f05b48/32.png) [@Lorygold](https://discuss.elastic.co/u/Lorygold)\
**Post date:** [May 16, 2023, 1:59pm UTC](https://discuss.elastic.co/t/event-type-field-in-system-module-logs-not-ecs-compliant/333579/1 "2023-05-16T13:59:40Z")

</div>

Good morning,

I activated the system module of Filebeat (version 8.7.1) in order to collect the ssh logins on an Ubuntu VM. I can see them on Kibana, but the `event.type` field is `info` event if it is an authentication log category.

The event.type should be `start` as described in the [ECS documentation](https://www.elastic.co/guide/en/ecs/master/ecs-allowed-values-event-category.html#ecs-event-category-authentication), shouldn’t it?

```auto
{
  "_index": ".ds-filebeat-8.7.1-2023.05.15-000001",
  "_source": {
       "log": {
           "file": {
               "path": "/var/log/auth.log"
           }
      },
      "event": {
           "kind": "event",
           "module": "system",
           "action": "ssh_login",
           "type": [
                "info"
            ],
           "category": [
                "authentication",
                "session"
            ],
            "dataset": "system.auth",
            "outcome": "success"
    },
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2023, 5:54pm UTC](https://discuss.elastic.co/t/event-type-field-in-system-module-logs-not-ecs-compliant/333579/3 "2023-06-14T17:54:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
