# Help with EQL Rule to Detect Unauthorized State Transitions for Traffic Lights

**URL:** <https://discuss.elastic.co/t/help-with-eql-rule-to-detect-unauthorized-state-transitions-for-traffic-lights/371956>\
**Category:** Elastic Security\
**Created:** [December 13, 2024, 11:02am UTC](https://discuss.elastic.co/t/help-with-eql-rule-to-detect-unauthorized-state-transitions-for-traffic-lights/371956 "2024-12-13T11:02:14Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [December 17, 2024, 11:14pm UTC](https://discuss.elastic.co/t/help-with-eql-rule-to-detect-unauthorized-state-transitions-for-traffic-lights/371956/4 "2024-12-17T23:14:56Z")

</div>

> [@Kuly2Fraise](#):
>
> Unsupported join key’ error on the ‘by’

@Kuly2Fraise this may be due to the hyphen in the field name ([best practices](https://www.elastic.co/guide/en/ecs/current/ecs-guidelines.html)😉 ); try [escaping the fieldname](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/4) with backticks.

Regarding the "empty response:"

1. Can you please share the full query that you're using?
2. Have you eliminated any broader issues like missing/conflicting mappings? Are you able to e.g. retrieve results with `sequence [any where event.light_state != null] [any where event.light_state != null]`
3. Can you verify that the data contains the sequence that you're looking for? Remember that they have to be sequential by `@timestamp`, and (now) contain the same `event.wlan-src` key.

---

_[View the full topic](https://discuss.elastic.co/t/help-with-eql-rule-to-detect-unauthorized-state-transitions-for-traffic-lights/371956)._
