# OSQuery Integration user.id is \[long\] but ECS is \[keyword\]

**URL:** <https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700>\
**Category:** Elastic Security\
**Created:** [May 6, 2023, 7:57am UTC](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700 "2023-05-06T07:57:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![oloughlinp](https://avatars.discourse-cdn.com/v4/letter/o/c68b51/32.png) [@oloughlinp](https://discuss.elastic.co/u/oloughlinp)\
**Post date:** [May 6, 2023, 7:57am UTC](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700/1 "2023-05-06T07:57:48Z")

</div>

Hi all,

I am trying to use some of the Windows prebuilt rules that rely on user.id in the eql query, but they are erroring out because my OSQuery manager indexes have user.id set to long, but the ECS standard (and what the windows/system integrations use) is for user.id to be keyword.

> verification\_exception Root causes: verification\_exception: verification\_exception: Found 1 problem line 4:33: Cannot use field [user.id] due to ambiguities being mapped as [2] incompatible types: [keyword] in --windows and linux logs-- , [long] in [.ds-logs-osquery\_manager-...].

I'm not sure if this is a bug with the OSQuery Manager integration, or an issue with something I did on my end. Has anyone encountered this before?

---

<div class="post-metadata">

**Author:** ![patrykkopycinski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrykkopycinski/32/45595_2.png) [@patrykkopycinski](https://discuss.elastic.co/u/patrykkopycinski)\
**Post date:** [May 8, 2023, 6:33pm UTC](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700/2 "2023-05-08T18:33:32Z")

</div>

@oloughlinp which version of the stack and osquery\_manager are you using?  
is it the initial version or have you migrated it? if so what was the initial version?

---

<div class="post-metadata">

**Author:** ![oloughlinp](https://avatars.discourse-cdn.com/v4/letter/o/c68b51/32.png) [@oloughlinp](https://discuss.elastic.co/u/oloughlinp)\
**Post date:** [May 10, 2023, 1:33pm UTC](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700/3 "2023-05-10T13:33:50Z")

</div>

Thanks @patrykkopycinski

Running on Elastic 8.7.0 and OSQuery Manager 1.7.2. We've upgraded two or three times over the last year.

I also found a bug report that hasn't been touched for the same issue: [[OSQuery] Non-compliant ECS field mappings causing conflicts: user.id, user.group.id, group.id · Issue #4507 · elastic/integrations · GitHub](https://github.com/elastic/integrations/issues/4507)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2023, 1:34pm UTC](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700/4 "2023-06-07T13:34:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
