# Rules failing

**URL:** <https://discuss.elastic.co/t/rules-failing/349470>\
**Category:** SIEM\
**Created:** [December 15, 2023, 5:44pm UTC](https://discuss.elastic.co/t/rules-failing/349470 "2023-12-15T17:44:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbreer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbreer/32/130059_2.png) [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Post date:** [December 15, 2023, 5:44pm UTC](https://discuss.elastic.co/t/rules-failing/349470/1 "2023-12-15T17:44:22Z")

</div>

Hi,

I have several rules that come back as Failed after running. I'm getting the following error for many rules. The field names for the unknown column message varies among the different rules.

```auto
An error occurred during rule execution: message: "verification_exception
              Root causes:
                             verification_exception: Found 2 problems
line 2:9: Unknown column [winlog.event_data.CallTrace]
line 12:6: Unknown column [winlog.event_data.TargetImage]"

```

I haven't looked at all the Failed rules yet, but so far, the ones I have looked at all depend on the Windows integration for the Elastic Agent. I look at the exported fields listed in the Windows integration and it includes both winlog.event\_data.CallTrace and winlog.event\_data.TargetImage but when I go to Stack Management \> Data Views \> logs-\* and search on those fields, they are not listed.

Not sure why the Elastic Agent isn't passing these fields back. Some of the other fields referenced as unknown columns are:

winlog.event\_data.GrantedAccess  
process.parent.name  
winlog.event\_data.EnabledPrivilegeList

I'm running on-prem enterprise licensed cluster at v8.11.2.

Thanks,  
Brad

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [December 16, 2023, 5:45pm UTC](https://discuss.elastic.co/t/rules-failing/349470/2 "2023-12-16T17:45:46Z")

</div>

Hi,

I would suggest finding the ingest pipeline that receives those logs, loading a test log, and testing the pipeline to intercept any errors during ingestion.

---

<div class="post-metadata">

**Author:** ![bbreer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbreer/32/130059_2.png) [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Post date:** [December 18, 2023, 7:25pm UTC](https://discuss.elastic.co/t/rules-failing/349470/3 "2023-12-18T19:25:17Z")

</div>

Thanks yago. Your suggestion made me go back and look again at the documentation for the Windows integration. In the Changelog section, 1.17.0 notes that most of the fields were moved to Sysmon operational fields. I didn't have the Sysmon channel enabled in the Windows integration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2024, 7:26pm UTC](https://discuss.elastic.co/t/rules-failing/349470/4 "2024-01-15T19:26:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
