# Fields missing in EQL sequence detection rule with building block alert as source

**URL:** <https://discuss.elastic.co/t/fields-missing-in-eql-sequence-detection-rule-with-building-block-alert-as-source/288483>\
**Category:** Elastic Security\
**Tags:** detection-rules, eql-elastic-query-language\
**Created:** [November 5, 2021, 10:05am UTC](https://discuss.elastic.co/t/fields-missing-in-eql-sequence-detection-rule-with-building-block-alert-as-source/288483 "2021-11-05T10:05:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![masual](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/masual/32/50236_2.png) [@masual](https://discuss.elastic.co/u/masual)\
**Post date:** [November 5, 2021, 10:05am UTC](https://discuss.elastic.co/t/fields-missing-in-eql-sequence-detection-rule-with-building-block-alert-as-source/288483/1 "2021-11-05T10:05:41Z")

</div>

Hi everyone,

I am implementing a set of Detection Rules to correlate events from different sources.

I created a Threshold Rule and marked it as "building block" since I plan to use the alerts it generates as the source event for an EQL Secuence rule.

The sequence is defined as follows:

```auto
 sequence with maxspan=1s
    [threat where network.protocol == "tcp"] by source.ip, destination.ip
    [any where event.kind == "signal" and signal.rule.description == "building-block-count-source-ip-destination-ip"] by source.ip, destination.ip

```

Thats the only way I found to include a building block alert in the EQL Sequence Detection Alert query.

Alerts are being fired, but they do not contain **source.ip** or **destination.ip** fields.

Analyzing the results by manually running the EQL query, I found out that for the first event, the ip fields are included as:

```auto
...
      "source" : {
        "geo" : { },
        "ip" : "192.168.1.10",
        "port" : "xxxx",
        "host" : {
          "name" : "xxxxx"
        }
...

```

but for the second event, the alert generated with the threshold rule, they are included as:

```auto
...
 "source.ip" : "192.168.1.10",
...

```

Should not the generated alert contain both **source.ip** and **destination.ip** , since these fields are present in both events matched by the EQL Sequence?

Cheers,

Manuel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2021, 10:05am UTC](https://discuss.elastic.co/t/fields-missing-in-eql-sequence-detection-rule-with-building-block-alert-as-source/288483/2 "2021-12-03T10:05:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
