# How to describe multiple users in ECS

**URL:** https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448
**Category:** Elasticsearch
**Tags:** ecs-elastic-common-schema
**Created:** [June 7, 2023, 2:43pm UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448 "2023-06-07T14:43:27Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![srilumpa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srilumpa/32/77018_2.png) [@srilumpa](https://discuss.elastic.co/u/srilumpa)
#### Post date: [June 7, 2023, 2:43pm UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448/1 "2023-06-07T14:43:27Z")

</div>

Hello,

I have a use case that is not described in the Elastic ECS documentation and I am looking for best practices on how to handle this.

So, basically, I have an application where an app admin can change multiple users at once. This action generates a single log in which is displayed the list of all users impacted by the change. Something like `{..., "ImpactedUsers": ["userA", "userB", "userC", ...], ... }`.

Which would be the best way to handle this? Having something like the following does not represent the reality of the event:

```json
{
  "user": {
    "target": {
      "id": ["userA", "userB", "userC", ...]
    }
  },
  "related": {
    "user": ["userA", "userB", "userC", ...]
  }
}

```

So I was thinking implementing something like this, but I am not sure this is supported/recommanded for the ECS normalization:

```json
{
  "user": {
    "target": [
      {"user": {"id": "userA"}},
      {"user": {"id": "userB"}},
      {"user": {"id": "userC"}},
      ...
    ]
  },
  "related": {
    "user": ["userA", "userB", "userC", ...]
  }
}

```

Thank you a lot.

---

<div class="post-metadata">

### Author: ![Sunile\_Manjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunile_manjee/32/111461_2.png) [@Sunile\_Manjee](https://discuss.elastic.co/u/Sunile_Manjee)
#### Post date: [June 11, 2023, 3:41am UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448/2 "2023-06-11T03:41:06Z")

</div>

> [@srilumpa](#):
>
> for the ECS normalization:

can you elaborate on which ECS field(s) or elastic solution set are you trying to map to?

---

<div class="post-metadata">

### Author: ![srilumpa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srilumpa/32/77018_2.png) [@srilumpa](https://discuss.elastic.co/u/srilumpa)
#### Post date: [June 12, 2023, 3:08pm UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448/3 "2023-06-12T15:08:18Z")

</div>

In my use case, the original data is an array containing identifiers of multiple users which are targetted by a configuration change. With this in mind, I thought to store this data into [`user.id`](https://www.elastic.co/guide/en/ecs/8.7/ecs-user.html#field-user-id), as recommended in the ECS documentation. More precisely in the [`user.target`](https://www.elastic.co/guide/en/ecs/8.7/ecs-user.html#_field_reuse_29) nested field. But since each identifier is related to a different user, I am not sure what would be the best practice to store the data.

---

<div class="post-metadata">

### Author: ![Sunile\_Manjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunile_manjee/32/111461_2.png) [@Sunile\_Manjee](https://discuss.elastic.co/u/Sunile_Manjee)
#### Post date: [June 12, 2023, 3:50pm UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448/4 "2023-06-12T15:50:58Z")

</div>

If I understand your question correctly, it appears that it aligns closely with the example provided in this link: [User Fields Usage and Examples | Elastic Common Schema (ECS) Reference [8.7] | Elastic](https://www.elastic.co/guide/en/ecs/8.7/ecs-user-usage.html#ecs-user-usage-iam).

---

<div class="post-metadata">

### Author: ![srilumpa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srilumpa/32/77018_2.png) [@srilumpa](https://discuss.elastic.co/u/srilumpa)
#### Post date: [June 13, 2023, 7:29am UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448/5 "2023-06-13T07:29:52Z")

</div>

Yes, I am already using `user.target` and `user.changes` to describe IAM events where one single user is modified (role modification, user deletion and so on...).

Question here is how can I handle a SINGLE event where MULTIPLE users are modified at once? I will have to handle an array to store each modified users but which method would be the best approach? Having `user.target.id` as an array where I store all the users' identifiers or having `user.target` as an array storing one object to describe each single user?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 11, 2023, 7:29am UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448/6 "2023-07-11T07:29:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
