# How to start a machine learning job to check if a user starts an application they normally do not use with Kibana

**URL:** <https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [May 6, 2022, 6:26am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094 "2022-05-06T06:26:56Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 6, 2022, 6:26am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/1 "2022-05-06T06:26:56Z")

</div>

I am trying to set up a machine learning job to detect when non admin users who normally do not use powershell start powershell.

I already saved a search function that shows powershell started logs, and filters the unimportant users:

`event.action: "created-process" and process.name: "powershell.exe" and not related.user: (*$ or adm_*)`

Now I thought the way to go is to use the data from the saved search in a machine learning job running a `rare detector` with `related.user as the field`. My thinking is that this way it finds when powershell was started, and registers an anomaly when someone runs it who does not usually use powershell. However, searching for `rare by "related.user"` does not seem to be an option in Elasticsearch. Does anyone have an example of how I could set this up?

---

<div class="post-metadata">

**Author:** ![droberts195](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/droberts195/32/17692_2.png) [@droberts195](https://discuss.elastic.co/u/droberts195)\
**Post date:** [May 6, 2022, 8:44am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/2 "2022-05-06T08:44:19Z")

</div>

What is the mapping of the `related.user` field? Is it a `keyword` field?

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 6, 2022, 8:49am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/3 "2022-05-06T08:49:34Z")

</div>

My apologies, I am quite new to Elasticsearch and kibana. How can I check this?

---

<div class="post-metadata">

**Author:** ![droberts195](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/droberts195/32/17692_2.png) [@droberts195](https://discuss.elastic.co/u/droberts195)\
**Post date:** [May 6, 2022, 9:12am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/4 "2022-05-06T09:12:43Z")

</div>

You can use the Elasticsearch Get Mapping API: [Get mapping API | Elasticsearch Guide [8.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)

It's easiest to call if you go to Dev console in Kibana, which you can get to by clicking "View in Console" on one of the examples on that docs page.

Things might be more complicated if you are searching across many indices and they have different mappings for this field. Which indices is your saved search configured to search?

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 6, 2022, 9:27am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/5 "2022-05-06T09:27:03Z")

</div>

I believe this is the only one:  
"indices": [  
"winlogbeat-\*"  
],

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 6, 2022, 9:32am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/6 "2022-05-06T09:32:52Z")

</div>

> [@droberts195](#):
>
> related.user

related.user does not appear in this file. Neither do host.name or user.name. Only username and hostname. but there is no entry for related.user or relateduser.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 6, 2022, 10:48am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/7 "2022-05-06T10:48:00Z")

</div>

I think the misunderstanding here is that you do not search for `rare by related.user` in the actual Elasticsearch query language, you accomplish that bit using an ML job (see [rarity analysis article](https://discuss.elastic.co/t/dec-4th-2018-en-ml-rarity-analysis-with-machine-learning/158979))

So, you need to:

1. Create a filtered search to come up with a version of the data set that you want - it seems that you've done this part. Save this search as a "Saved Search"
2. Use that "Saved Search" as the [basis of your ML job](https://discuss.elastic.co/t/creating-ml-using-saved-search/149570)
3. Configure your ML job to do rarity analysis using the appropriate fields in the data.

I hope this helps

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 9, 2022, 6:02am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/8 "2022-05-09T06:02:41Z")

</div>

Thats what i am trying, but when i set up an advanced machine learning job related.user does not appear in the field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/2/a23758f69273f2d9935a59ec080ba2210f485768.png)

I tried using user.name.text as alternative:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/efe24b87ce1bac10b533c69e71d6c03bac033659.png)

The datafeed preview shows correct data but i still cant start the job:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/9/19fa51a520a3a325fba106292ac6f859a5f64184.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 9, 2022, 11:37am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/9 "2022-05-09T11:37:45Z")

</div>

The UI is suggesting you use `related.user.keyword` (the `keyword` type version of `related.user`). This will work for you.

If you did not know this, the index "[mappings](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)" are definitions of the fields and their types. [A long time ago](https://www.elastic.co/blog/strings-are-dead-long-live-strings), string-based fields (like fields that defined the names of things) were replaced with `text` and `keyword` types.

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 9, 2022, 11:44am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/10 "2022-05-09T11:44:22Z")

</div>

I tried that, but it shows 0 related users. Only timestamps:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37476b7e301be93de9ec8487be453d2ac86e5545.png)

And when i look for a user that definitely exists it cannot be found:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/1/91088e1db272cfec8c1b16ba9c2ee2f20c53f7cf.png)

I aslo tried using the user.name.text option which does show the correct usernames in the data preview, but apparently i cant use it:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7bffe60e00044533e47e94b6a0d5d83db887cd27.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2022, 11:44am UTC](https://discuss.elastic.co/t/how-to-start-a-machine-learning-job-to-check-if-a-user-starts-an-application-they-normally-do-not-use-with-kibana/304094/11 "2022-06-06T11:44:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
