# Vulnerability is not being allowed in event.category

**URL:** <https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [July 5, 2023, 12:44pm UTC](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674 "2023-07-05T12:44:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hodgepodge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hodgepodge/32/122363_2.png) [@hodgepodge](https://discuss.elastic.co/u/hodgepodge)\
**Post date:** [July 5, 2023, 12:44pm UTC](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674/1 "2023-07-05T12:44:54Z")

</div>

I am seeing this failure while testing pipeline of integration:  
[0] parsing field value failed: field "event.category"'s value "vulnerability" is not one of the allowed values (authentication, configuration, database, driver, file, host, iam, intrusion\_detection, malware, network, package, process, registry, session, threat, web)

When ECS states the following:  
event.category/keyword  
Description: This is one of four ECS Categorization Fields, and indicates the second level in the ECS category hierarchy.  
event.category represents the "big buckets" of ECS categories. For example, filtering on event.category:process yields all events relating to process activity. This field is closely related to event.type, which is used as a subcategory.  
This field is an array. This will allow proper categorization of some events that fall in multiple categories.  
type: keyword  
Note: this field should contain an array of values.  
Important: The field value must be one of the following:  
api, authentication, configuration, database, driver, email, file, host, iam, intrusion\_detection, library, malware, network, package, process, registry, session, threat, **vulnerability** , web  
To learn more about when to use which value, visit the page allowed values for event.category

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [July 5, 2023, 7:51pm UTC](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674/2 "2023-07-05T19:51:08Z")

</div>

What version of ECS is the integration package specifying? For example, the `zeek` package is targeting `v8.8.0` here: [integrations/packages/zeek/\_dev/build/build.yml at main · elastic/integrations · GitHub](https://github.com/elastic/integrations/blob/main/packages/zeek/_dev/build/build.yml#L3)

The `vulnerability` category was added in [ECS 8.6](https://github.com/elastic/ecs/releases/tag/v8.6.0), and the version of ECS currently used by the package may be pre-8.6.

---

<div class="post-metadata">

**Author:** ![hodgepodge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hodgepodge/32/122363_2.png) [@hodgepodge](https://discuss.elastic.co/u/hodgepodge)\
**Post date:** [July 5, 2023, 7:59pm UTC](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674/3 "2023-07-05T19:59:51Z")

</div>

Eric,  
I believe we are using ECS version 8.5.1 which would explain this issue. I will check with the content team and if so upgrade our version to 8.6 minimum.  
Thank you for the quick response,  
Bruce

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2023, 8:00pm UTC](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674/4 "2023-08-02T20:00:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
