# Problem with EQL sequence by with field containing reserved characters

**URL:** <https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295>\
**Category:** Elastic Security\
**Created:** [April 26, 2024, 1:27pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295 "2024-04-26T13:27:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![llafortezza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/llafortezza/32/133894_2.png) [@llafortezza](https://discuss.elastic.co/u/llafortezza)\
**Post date:** [April 26, 2024, 1:27pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/1 "2024-04-26T13:27:41Z")

</div>

Hi,  
i have the following error  
line 1:56: mismatched input '.0' expecting {'with', '[', '!['}  
with this EQL query:

```auto
sequence by azure.auditlogs.properties.target_resources.0.id with maxspan=24h 
[any where event.dataset == "azure.auditlogs" and event.outcome in ("Success", "success") and event.action == "Add user"]
[any where event.dataset == "azure.auditlogs" and event.outcome in ("Success", "success") and event.action == "Delete user"]

```

I tried to escape the 0 and surrounding the field with "" but i got the following errors:  
line 1:57: token recognition error at: ''  
line 1:11: Unsupported join key  
Do you have any ideas to solve this problem ?

---

<div class="post-metadata">

**Author:** ![Maxim\_Palenov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxim_palenov/32/122504_2.png) [@Maxim\_Palenov](https://discuss.elastic.co/u/Maxim_Palenov)\
**Post date:** [April 26, 2024, 2:22pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/2 "2024-04-26T14:22:48Z")

</div>

Hi @llafortezza and welcome to the Elastic community!

Could you clarify what you want to achieve with this EQL?

Checking ECS mappings for [`azure.auditlogs.properties.target_resources`](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-azure.html#_target_resources) I see this

```auto
azure.auditlogs.properties.target_resources.*.id
ID

type: keyword

```

There is a wildcard `*` inside which will match any field name. Do you have `0` field in `azure.auditlogs.properties.target_resources`?

---

<div class="post-metadata">

**Author:** ![llafortezza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/llafortezza/32/133894_2.png) [@llafortezza](https://discuss.elastic.co/u/llafortezza)\
**Post date:** [April 26, 2024, 2:43pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/3 "2024-04-26T14:43:32Z")

</div>

Hi Maxim,  
with this EQL i want to replicate this sigma rule.

> <https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_ad_account_created_deleted.yml>

Yes, i have 0 field in azure.auditlogs.properties.target\_resources.  
I tried to use `azure.auditlogs.properties.target_resources.*.id` as field but i got the following error.  
line 1:57: no viable alternative at input 'azure.auditlogs.properties.target\_resources.\*'

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [April 26, 2024, 4:31pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/4 "2024-04-26T16:31:56Z")

</div>

@llafortezza you're correct that the numeric field name is what's causing the issue here. You should be able to [escape the field name](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql-syntax.html#eql-syntax-escape-a-field-name) in order to allow EQL to parse it correctly:

```auto
sequence by `azure.auditlogs.properties.target_resources.0.id` with maxspan=24h 
[any where event.dataset == "azure.auditlogs" and event.outcome in ("Success", "success") and event.action == "Add user"]
[any where event.dataset == "azure.auditlogs" and event.outcome in ("Success", "success") and event.action == "Delete user"]

```

---

<div class="post-metadata">

**Author:** ![llafortezza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/llafortezza/32/133894_2.png) [@llafortezza](https://discuss.elastic.co/u/llafortezza)\
**Post date:** [April 27, 2024, 12:16pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/5 "2024-04-27T12:16:59Z")

</div>

Thanks @RylandHerrick 😀 Now it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2024, 12:17pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/6 "2024-05-25T12:17:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
