# Problems using ecs

**URL:** https://discuss.elastic.co/t/problems-using-ecs/381340
**Category:** Elastic Observability
**Tags:** ecs-elastic-common-schema
**Created:** [August 26, 2025, 9:02am UTC](https://discuss.elastic.co/t/problems-using-ecs/381340 "2025-08-26T09:02:01Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Ruslan\_Hafizov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruslan_hafizov/32/139786_2.png) [@Ruslan\_Hafizov](https://discuss.elastic.co/u/Ruslan_Hafizov)
#### Post date: [August 26, 2025, 9:02am UTC](https://discuss.elastic.co/t/problems-using-ecs/381340/1 "2025-08-26T09:02:01Z")

</div>

I try to use ecs to standardize various logs from different applications. I don't always manage to find a field that suits the situation, especially when it comes to user authorization/authentication. I would like to provide an example of some logs and discuss whether it is possible to store some of the information in the standard ECS schema. Examples:

`User s3 logged in via SSH with MFA enabled (true), using a web terminal named ko-ko.`

user.name: s3

event.action: login

user.authentication.mfa: true (e)

user.authentication.count: 1 (e)

user.login.type: web-terminal (e)

user.login.terminal: ko-ko (e)

`User s3 uploaded data to preferences-api with security settings.`

user.name: s3

event.action: upload

label.resource.name: preferences-api (e)

label.resource.params: security (e)

`User gen-ai used 5 commands to generate images. Output: "images1.png, images2.png will be generated."`

user.name: gen-ai

user.session.command\_count: 5 (e)

event.action: generate images

label.output: "images1.png, images2.png will be generated" (e)

Fields marked with (e) indicate that I did not find a suitable field in the standard ecs schema. Please share your experience if you have encountered storing this type of data or know a suitable field from the standard schema. Additionally, explain why you chose this particular field. I would appreciate your feedback.

---

<div class="post-metadata">

### Author: ![Quan.Nguyen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quan.nguyen/32/136581_2.png) [@Quan.Nguyen](https://discuss.elastic.co/u/Quan.Nguyen)
#### Post date: [August 29, 2025, 6:35pm UTC](https://discuss.elastic.co/t/problems-using-ecs/381340/2 "2025-08-29T18:35:48Z")

</div>

Thank you [Ruslan\_Hafizov](https://discuss.elastic.co/u/ruslan_hafizov) for raising the issue, as you said there are no suitable definitions for the items that you’ve flagged. I’ve logged an issue with the ECS repository - [ticket](https://github.com/elastic/ecs/issues/2520) - to track your suggestion. We’ll go through a triaging process with the team.

Regarding the gen\_ai fields, we recently added beta fields for gen\_ai - (start here) [link](https://github.com/elastic/ecs/blob/0710daa3aab83838c4b2cbfc94cc685d9197172d/generated/ecs/ecs_flat.yml#L5844) - which I think you should review to see if there are any suitable fields for the items you’ve mentioned

Doing a quick scan possibly these fields might be applicable for some of the fields. There are still some values that might not have a direct mapping to your example

```auto
gen_ai.output.type
gen_ai.operation.name
gen_ai.response.finish_reasons (possible error scenarios)

```
