# Field for active/passive?

**URL:** https://discuss.elastic.co/t/field-for-active-passive/307080
**Category:** Elasticsearch
**Tags:** ecs-elastic-common-schema
**Created:** [June 13, 2022, 11:21pm UTC](https://discuss.elastic.co/t/field-for-active-passive/307080 "2022-06-13T23:21:13Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)
#### Post date: [June 13, 2022, 11:21pm UTC](https://discuss.elastic.co/t/field-for-active-passive/307080/1 "2022-06-13T23:21:13Z")

</div>

In ECS Elastic Common Schema...

Is there a field for indicating if a service (or anything) is active or passive?

I tried looking through the spec but was unable to find anything.

---

<div class="post-metadata">

### Author: ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)
#### Post date: [June 14, 2022, 2:29pm UTC](https://discuss.elastic.co/t/field-for-active-passive/307080/2 "2022-06-14T14:29:12Z")

</div>

What about `service.state`?

---

<div class="post-metadata">

### Author: ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)
#### Post date: [June 15, 2022, 4:56pm UTC](https://discuss.elastic.co/t/field-for-active-passive/307080/3 "2022-06-15T16:56:22Z")

</div>

_Oh._ I missed that. Thanks very much for helping me find it.

I think it _might_ be a good field for this.

It's very generic, as "state" could refer to so much. But I would imagine activeness/passiveness would be a major potential / common use.

I think if we adopted this field for this particular purpose, we'd want to internally override the schema. That is, since the schema is defined as names, types, _and meanings_, we'd have to override the meaning to indicate that `service.state` specifically means "activeness or passiveness", not other potential meanings of "state", and even provide an enumeration of values (a fourth part of the schema that's rarely discussed).

We've designed a three-part master schema that's composed of ECS at the base, company-specific fields atop that, and service-specific fields atop that. While the company-specific fields have mostly been namespaced to avoid colliding, something like `service.XYZ.state`, I'm only now realizing that some company-specific fields might need to be name-identical overrides of ECS. (That is, compliant with ECS, but with locally strict requirements.)

I think it could work.

Learning a lot about schema adoption and working with ECS. Thanks again for being so responsive and helpful.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 13, 2022, 4:56pm UTC](https://discuss.elastic.co/t/field-for-active-passive/307080/4 "2022-07-13T16:56:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
