# Valid values for service.state

**URL:** <https://discuss.elastic.co/t/valid-values-for-service-state/373766>\
**Category:** Logs\
**Tags:** ecs-elastic-common-schema\
**Created:** [January 28, 2025, 12:25pm UTC](https://discuss.elastic.co/t/valid-values-for-service-state/373766 "2025-01-28T12:25:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelunik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kelunik/32/120140_2.png) [@kelunik](https://discuss.elastic.co/u/kelunik)\
**Post date:** [January 28, 2025, 12:25pm UTC](https://discuss.elastic.co/t/valid-values-for-service-state/373766/1 "2025-01-28T12:25:40Z")

</div>

I have (long-running) processes that have a starting, running and shutdown phase. I want to filter logs to only show the running phase. I looked at ECS and found `service.state` as a field that might be suitable, however, there aren't any valid values documented.

Is this what I should use? Are there any standard values? Any good alternative field that could fit?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 28, 2025, 5:07pm UTC](https://discuss.elastic.co/t/valid-values-for-service-state/373766/2 "2025-01-28T17:07:16Z")

</div>

Hi @kelunik,

I can't find any specification for that in ECS or OpenTelemetry. Looking at the usage of the fields by [the official integrations](https://github.com/elastic/integrations) I see "UP" and "DOWN" as possible values, but to me it also sounds reasonable for the states you mentioned.
