# Multiple Machine Learning Alerts by Influencer Field failing Unknown column \[job\_id\]

**URL:** <https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743>\
**Category:** SIEM\
**Created:** [August 18, 2026, 7:29am UTC](https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743 "2026-08-18T07:29:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [August 18, 2026, 7:29am UTC](https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743/1 "2026-08-18T07:29:47Z")

</div>

Hello,

I am seeing the prebuilt rule **Multiple Machine Learning Alerts by Influencer Field** fail with:

```auto
verification_exception
Unknown column [job_id]
Unknown column [influencers.influencer_field_name]
Unknown column [influencers.influencer_field_values]

```

The ML rules themselves are working and generating Security alerts.

Example ML alert `_source` contains:

```auto
"job_id": "auth_rare_hour_for_a_user",
"influencers": [
  {
    "influencer_field_name": "source.ip",
    "influencer_field_values": [
      "10.x.x.x"
    ]
  }
]

```

However:

```auto
GET .alerts-security*/_field_caps?fields=job_id,influencers.influencer_field_name,influencers.influencer_field_values

```

returns:

```auto
"fields": {}

```

And:

```auto
GET .alerts-security*/_mapping/field/job_id

```

shows no mapping for the field.

So the fields exist in `_source`, but are not mapped/indexed, while the prebuilt ES|QL rule directly references them.

The failing query includes:

```auto
COUNT_DISTINCT(job_id)
VALUES(influencers.influencer_field_values)
VALUES(influencers.influencer_field_name)

```

This looks like a mismatch between the Security ML alert schema and the prebuilt higher-order rule.

Is this a known issue, or is there an expected mapping/template that should contain these ML fields?

Best regards,

Willem D'Haese

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2026, 7:30am UTC](https://discuss.elastic.co/t/multiple-machine-learning-alerts-by-influencer-field-failing-unknown-column-job-id/389743/2 "2026-09-15T07:30:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
