# Problem with EQL sequence by with field containing reserved characters

**URL:** <https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295>\
**Category:** Elastic Security\
**Created:** [April 26, 2024, 1:27pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295 "2024-04-26T13:27:41Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [April 26, 2024, 4:31pm UTC](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295/4 "2024-04-26T16:31:56Z")

</div>

@llafortezza you're correct that the numeric field name is what's causing the issue here. You should be able to [escape the field name](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql-syntax.html#eql-syntax-escape-a-field-name) in order to allow EQL to parse it correctly:

```auto
sequence by `azure.auditlogs.properties.target_resources.0.id` with maxspan=24h 
[any where event.dataset == "azure.auditlogs" and event.outcome in ("Success", "success") and event.action == "Add user"]
[any where event.dataset == "azure.auditlogs" and event.outcome in ("Success", "success") and event.action == "Delete user"]

```

---

_[View the full topic](https://discuss.elastic.co/t/problem-with-eql-sequence-by-with-field-containing-reserved-characters/358295)._
