# Tags for security-related encoding issues

**URL:** <https://discuss.elastic.co/t/tags-for-security-related-encoding-issues/281466>\
**Category:** Logstash\
**Created:** [August 14, 2021, 11:58pm UTC](https://discuss.elastic.co/t/tags-for-security-related-encoding-issues/281466 "2021-08-14T23:58:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cknz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cknz/32/9640_2.png) [@cknz](https://discuss.elastic.co/u/cknz)\
**Post date:** [August 14, 2021, 11:58pm UTC](https://discuss.elastic.co/t/tags-for-security-related-encoding-issues/281466/1 "2021-08-14T23:58:42Z")

</div>

Let's say you have some logstash module or Ruby configuration that cleans up / parses / etc. logs, and it comes across something that would be illegal (Eg. illegal UTF-8 encoding sequence which if it were not sanitized could threaten the pipeline).

Obviously you would need to clean this up, but from a security point of a view (ie. as a SIEM) you would want to know that this has been done and that this (eg. web access log) signified something noteworthy. If I were to merely fix up the request (eg. by replacing the illegal encoding sequence with a Unicode replacement character) that would remove visibility of what was special about this request.

So what I want to know is this:

- What is a good way of safely showing the true nature of the request?
- How (preferably in an ECS compliant way) should I signify that this request is highly suspect? ECS doesn't seem to offer any guidance on tags, from what I can see.

I don't think it would be appropriate to use the ECS error.\* fields, because I'm not saying that the log entry describes an error event... possibly the the threat.\* fields might be useful, but I didn't see anything that seemed to match (tactics, techniques in the Mitre ATT&CK framework).

What I want to end up happening is that if I send this to Elasticsearch I want the SIEM product etc. to have a good chance of recognising that this log indicates something of concern and should probably boost any threat evaluation.

Cheers,  
Cameron

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2021, 11:59pm UTC](https://discuss.elastic.co/t/tags-for-security-related-encoding-issues/281466/2 "2021-09-11T23:59:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
