# Service names

**URL:** <https://discuss.elastic.co/t/service-names/329265>\
**Category:** Elastic Observability\
**Tags:** ecs-elastic-common-schema\
**Created:** [April 4, 2023, 2:15am UTC](https://discuss.elastic.co/t/service-names/329265 "2023-04-04T02:15:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [April 4, 2023, 2:15am UTC](https://discuss.elastic.co/t/service-names/329265/1 "2023-04-04T02:15:46Z")

</div>

Howdy, ECS developers and ontology fans, I have some thoughts and questions:

In the `service.*` field set I feel there are two distinct “naming” purposes I want to achieve.

1. I want a _unique identifier_ I can use to collate logs, or to reference between logs and other systems like a service registry, cost accounting system, or metrics dashboard.
2. I want a human-readable, colloquial _name_ or _title_ for the service. Engineers may know this service as the “PII Filtering Processor” or “Test API”. _This information should tolerate not being unique._

For the unique identifier, service.id does the job. I believe this is what this field was meant for.

For the colloquial title, what you might expect an engineer to refer to their service as in conversation, I _think_ `service.name` might be the right field.  
But I have questions given [the description](https://www.elastic.co/guide/en/ecs/current/ecs-service.html#field-service-name).

> This allows for distributed services that run on multiple hosts to correlate the related instances based on the name.

This usage confuses me since I don’t expect `service.name` to necessarily be unique, _and_ the fact that `service.id` exists and is ideal for this usage.

**Are we saying that maybe you could correlate distributed instance logs for a service using service.name iff it happens to be unique? And aren’t implying that it should be unique?**

---

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [April 27, 2023, 11:21pm UTC](https://discuss.elastic.co/t/service-names/329265/2 "2023-04-27T23:21:13Z")

</div>

I get the impression the community-based discussion around ECS development might not happen in these forums.

Is it better to prompt discussion maybe by submitting RFCs?
