# Timelines Event Renderer - Why I don't see this in my timeline

**URL:** <https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258>\
**Category:** SIEM\
**Created:** [May 6, 2020, 4:47am UTC](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258 "2020-05-06T04:47:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilo21](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilo21/32/66272_2.png) [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Post date:** [May 6, 2020, 4:47am UTC](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258/1 "2020-05-06T04:47:44Z")

</div>

So, I was parsing Fortigate events in a compliant way to ECS with some enrichment by adding categorization fields with logstash but instead of getting this :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f53c211123fb84e432590c0fb86089581940266.png)

I get this :

 ![2020-05-06 04_31_20-BUREAU-1 - Desktop Viewer](https://us1.discourse-cdn.com/elastic/original/3X/5/3/53e7268d980a9b9a4313a9343a73859c33a63007.png)

Even though I respected categorization field in the event mapping to the ECS documentation :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fe4e20a3d8307c09226ba2c795e981bc958828bf.png)

Here is a small part my logstash ECS mapping :

```auto
if "utm" in [type] and "1059028704" in [logid] {
                        if "pass" in [action] {
                                mutate {
                                add_tag => ["utm"]
                                add_field => { "event.module" => "UTM" }
                                add_field => { "observer.type" => "firewall" }
                                add_field => { "event.kind" => "event" }
                                add_field => { "event.category" => "network" }
                                add_field => { "event.code" => "Utm Allowed" }
                                add_field => { "event.id" => "1059028704" }
                                add_field => { "event.type" => "allowed" }
                                add_field => { "event.outcome" => "success" }
                                }
                        } else if "block" in [action] {
                                mutate {
                                add_tag => ["utm"]
                                add_field => { "event.module" => "UTM" }
                                add_field => { "observer.type" => "firewall" }
                                add_field => { "event.kind" => "event" }
                                add_field => { "event.category" => "network" }
                                add_field => { "event.code" => "Utm Denied" }
                                add_field => { "event.id" => "1059028704" }
                                add_field => { "event.type" => "denied" }
                                add_field => { "event.outcome" => "failure" }
                                }
                        }
mutate {

                        lowercase => ["service"]
                        lowercase => ["app"]
                        copy => { "srcip" => "source.ip" }
                        copy => { "dstip" => "destination.ip" }
                        #rename => { "xauthuser" => "user.name" }
                        #rename => { "vpntunnel" => "group.id" }
                        rename => { "logid" => "event.id" }
                        rename => { "devname" => "observer.hostname" }
                        rename => { "dir" => "netowrk.direction" }
                        rename => { "status" => "event.outcome" }
                        rename => { "srcport" => "source.port" }
                        rename => { "dstport" => "destination.port" }
                        rename => { "srcintf" => "observer.ingress.interface.name" }
                        rename => { "dstintf" => "observer.egress.interface.name" }
                        rename => { "sentbyte" => "source.bytes" }
                        rename => { "rcvdbyte" => "destination.bytes" }
                        rename => { "sentpkt" => "source.packets" }
                        rename => { "rcvdpkt" => "destination.packets" }
                        rename => { "proto" => "network.iana_number" }
                        #copy => { "service" => "service.type" }
                        copy => { "service" => "network.protocol" }
                        rename => { "action" => "event.action" }
                        rename => { "app" => "network.application" }
                        rename => { "url" => "url.path" }
                        rename => { "hostname" => "url.domain" }
                }

```

Am I missing some fields ? can you provide extra info about this since there is no way to inspect what timelines request are like unlike the other visualizations.

Thank you

---

<div class="post-metadata">

**Author:** ![hilo21](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilo21/32/66272_2.png) [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Post date:** [May 6, 2020, 5:13am UTC](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258/2 "2020-05-06T05:13:30Z")

</div>

Okey this was quick 😃 , I found a reddit answer for this :

> **[r/elasticsearch - How to obtain this kind of view in SIEM App ?](https://www.reddit.com/r/elasticsearch/comments/ftmxjj/how_to_obtain_this_kind_of_view_in_siem_app/)**
>
> 10 votes and 5 comments so far on Reddit

I changed my `event.category` from `network` to `network_traffic` and it solved the issue. I wonder why though ?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79f9ef4ddf1f9515daaa9bb7fe76675ea20f8b66.png)

---

<div class="post-metadata">

**Author:** ![Xavier\_Mouligneau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_mouligneau/32/49188_2.png) [@Xavier\_Mouligneau](https://discuss.elastic.co/u/Xavier_Mouligneau)\
**Post date:** [May 6, 2020, 11:26am UTC](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258/3 "2020-05-06T11:26:42Z")

</div>

Hi Hilo21,

Great that you find a solution to your problem, I just wanted to add that you can inspect the query of timeline by clicking on the gear\>inspect, you will be able to inspect the query if you have a valid/working query in timeline.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b0c4e317109a802d5cbcb03104329310e9843a51.png)

---

<div class="post-metadata">

**Author:** ![hilo21](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilo21/32/66272_2.png) [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Post date:** [May 6, 2020, 9:14pm UTC](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258/4 "2020-05-06T21:14:15Z")

</div>

Thanks Xavier, very helpful

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2020, 9:14pm UTC](https://discuss.elastic.co/t/timelines-event-renderer-why-i-dont-see-this-in-my-timeline/231258/5 "2020-06-03T21:14:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
