# Rule Failure

**URL:** <https://discuss.elastic.co/t/rule-failure/364792>\
**Category:** Elastic Security\
**Created:** [August 12, 2024, 6:37pm UTC](https://discuss.elastic.co/t/rule-failure/364792 "2024-08-12T18:37:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ETFJeff](https://avatars.discourse-cdn.com/v4/letter/e/8edcca/32.png) [@ETFJeff](https://discuss.elastic.co/u/ETFJeff)\
**Post date:** [August 12, 2024, 6:37pm UTC](https://discuss.elastic.co/t/rule-failure/364792/1 "2024-08-12T18:37:31Z")

</div>

Hi,  
I have the following rule failure:

/An error occurred during rule execution: message: "verification\_exception  
Root causes:  
verification\_exception: Found 1 problem  
line 3:3: Unknown column [winlog.event\_data.AttributeLDAPDisplayName], did you mean [winlog.event\_data.AttributeValue]?"

I am unsure on how to correct this. Any ideas?  
Thanks

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [August 13, 2024, 3:02am UTC](https://discuss.elastic.co/t/rule-failure/364792/2 "2024-08-13T03:02:10Z")

</div>

Hi @ETFJeff , welcome to out community.

Have you verified Field Names in the Index Pattern?

- Go to **Kibana** and navigate to **Stack Management \> Index Patterns**.
- Find the index pattern that your rule is querying against (likely something like `winlogbeat-*` if you’re using Winlogbeat).
- Check if the field `winlog.event_data.AttributeLDAPDisplayName` actually exists.

---

<div class="post-metadata">

**Author:** ![ETFJeff](https://avatars.discourse-cdn.com/v4/letter/e/8edcca/32.png) [@ETFJeff](https://discuss.elastic.co/u/ETFJeff)\
**Post date:** [August 13, 2024, 2:16pm UTC](https://discuss.elastic.co/t/rule-failure/364792/3 "2024-08-13T14:16:27Z")

</div>

Hi,

Thanks. Glad to be working in Elastic but also I am very new so I have to admit I am quite challenged.

I think Index Patterns is not called Data Views?

I looking in Data Views and the field `winlog.event_data.AttributeLDAPDisplayName does not exist there.```

``

What are my options to correct this? Should I try to remove the field from the query or add the field to the data view?

Sorry I am very new to elastic so not familiar with best ways to correct issues like this.

Thanks

Jeff

---

<div class="post-metadata">

**Author:** ![Jonhnathan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonhnathan/32/98445_2.png) [@Jonhnathan](https://discuss.elastic.co/u/Jonhnathan)\
**Post date:** [September 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/rule-failure/364792/4 "2024-09-03T17:08:33Z")

</div>

Hey @ETFJeff, apologies for the delay in responding. The warning message indicates that no events containing this field have been ingested yet. Since most fields under `winlog.event_data.*` are dynamically parsed, the field will only appear in the mapping once a document with that field is ingested.

This field is associated with Active Directory monitoring. I would evaluate if it is relevant to your environment. If it is, you can find setup instructions for enabling the necessary audit policies on your domain controllers in the Setup section. If it's not relevant, you may want to consider disabling the rule.

---

<div class="post-metadata">

**Author:** ![Jonhnathan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonhnathan/32/98445_2.png) [@Jonhnathan](https://discuss.elastic.co/u/Jonhnathan)\
**Post date:** [September 3, 2024, 5:09pm UTC](https://discuss.elastic.co/t/rule-failure/364792/5 "2024-09-03T17:09:59Z")

</div>

Issues related to detection rules can be brought more directly to the responsible team attention by opening an issue in our github repo: [Issues · elastic/detection-rules · GitHub](https://github.com/elastic/detection-rules/issues)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2024, 5:10pm UTC](https://discuss.elastic.co/t/rule-failure/364792/6 "2024-10-01T17:10:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
