# Set custom event.category field to execute EQL in detection rules

**URL:** <https://discuss.elastic.co/t/set-custom-event-category-field-to-execute-eql-in-detection-rules/287986>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [October 29, 2021, 9:48am UTC](https://discuss.elastic.co/t/set-custom-event-category-field-to-execute-eql-in-detection-rules/287986 "2021-10-29T09:48:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Silver137](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Post date:** [October 29, 2021, 9:48am UTC](https://discuss.elastic.co/t/set-custom-event-category-field-to-execute-eql-in-detection-rules/287986/1 "2021-10-29T09:48:12Z")

</div>

I'm trying to set up a custom detection rule based in EQL sequence matching, with the trouble that the field that I chose for custom event.category in ECS It's really the ECS tags field in my indexed documents

I'm in the situation where, my EQL works in context of API-EQL queries where I can specify the field: "event\_category\_field": "tags"

This works:  
 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45ba1358a60ed6cee98df797d5def718b585791d.png)

But when trying to create the rule in security features:

![imagen](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9dac7b03317d444decfd3e557e193ca35d8032e.png)

![imagen](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d25a05460e3b11237bb23fce29b45b3ee14d9cf4.png)

If there isn't another solution how can I rename the field over the index ?

---

<div class="post-metadata">

**Author:** ![masual](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/masual/32/50236_2.png) [@masual](https://discuss.elastic.co/u/masual)\
**Post date:** [November 5, 2021, 10:47am UTC](https://discuss.elastic.co/t/set-custom-event-category-field-to-execute-eql-in-detection-rules/287986/2 "2021-11-05T10:47:32Z")

</div>

I run into the same issue and use the "workarround" of using "any" as the event category filter and then filter in the where statement. Maybe something like this does the trick for you:

```auto
any where tcp.srcport == "3389" 

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2021, 10:47am UTC](https://discuss.elastic.co/t/set-custom-event-category-field-to-execute-eql-in-detection-rules/287986/3 "2021-12-03T10:47:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
