# "This event cannot be analyzed since it has incompatible field mappings" On my own log

**URL:** <https://discuss.elastic.co/t/this-event-cannot-be-analyzed-since-it-has-incompatible-field-mappings-on-my-own-log/280319>\
**Category:** Elastic Security\
**Created:** [August 3, 2021, 1:46pm UTC](https://discuss.elastic.co/t/this-event-cannot-be-analyzed-since-it-has-incompatible-field-mappings-on-my-own-log/280319 "2021-08-03T13:46:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nberens](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@nberens](https://discuss.elastic.co/u/nberens)\
**Post date:** [August 3, 2021, 1:46pm UTC](https://discuss.elastic.co/t/this-event-cannot-be-analyzed-since-it-has-incompatible-field-mappings-on-my-own-log/280319/1 "2021-08-03T13:46:18Z")

</div>

Hello,

i am currently integrating our watchguard vpn logs into our Elasticsearch siem.

I basically build a logstash rule that takes its Syslog output and mapps it onto ECS.

While everthing now works as expected, i noticed that when i create Detections for it, i can't use the Analyze button.

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fee7b20e45f4e38410ab89183537b7ec8792f0e9.png)

Is there a way to figure out which field is wrongly mapped or which data this function needs?

---

<div class="post-metadata">

**Author:** ![thedanielmatt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thedanielmatt/32/93284_2.png) [@thedanielmatt](https://discuss.elastic.co/u/thedanielmatt)\
**Post date:** [August 17, 2021, 2:35pm UTC](https://discuss.elastic.co/t/this-event-cannot-be-analyzed-since-it-has-incompatible-field-mappings-on-my-own-log/280319/2 "2021-08-17T14:35:55Z")

</div>

Seeing this too, except in an Auditbeat entry.

I resolved the only unknown field I found, "network direction", but that did not resolve the issue.

Any luck figuring it out?

---

<div class="post-metadata">

**Author:** ![thedanielmatt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thedanielmatt/32/93284_2.png) [@thedanielmatt](https://discuss.elastic.co/u/thedanielmatt)\
**Post date:** [August 17, 2021, 2:43pm UTC](https://discuss.elastic.co/t/this-event-cannot-be-analyzed-since-it-has-incompatible-field-mappings-on-my-own-log/280319/3 "2021-08-17T14:43:56Z")

</div>

I'm guessing this explains it:

> **[Visual event analyzer | Elastic Security Solution \[7.16\] | Elastic](https://www.elastic.co/guide/en/security/7.16/visual-event-analyzer.html)**

Looks like it may only be compatible with events from Winlogbeat with the sysmon module, or the endpoint agent.

### 

Find events to analyze[edit](https://github.com/elastic/security-docs/edit/7.x/docs/detections/visual-event-analyzer.asciidoc)

You can only visualize events triggered by hosts configured with the Elastic Endpoint Security Integration or any sysmon data from `winlogbeat` .

In KQL, this translates to any event with the `agent.type` set to either:

- `endpoint`
- `winlogbeat` with `event.module` set to `sysmon`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2021, 2:44pm UTC](https://discuss.elastic.co/t/this-event-cannot-be-analyzed-since-it-has-incompatible-field-mappings-on-my-own-log/280319/4 "2021-09-14T14:44:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
