# Why can't I use user.name as field in machine learning job, but the standard jobs can?

**URL:** <https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [May 9, 2022, 11:27am UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245 "2022-05-09T11:27:57Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 9, 2022, 11:27am UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/1 "2022-05-09T11:27:57Z")

</div>

Why is it not possible for me to use the user.name field in the "by field" section of a machine learning job, but the standard jobs have no problem with it?  
As you can see it is not an option for me:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/a/dabb973b3a945cd3976f6b4e8b77940d8291c281.png)

But the standard jobs can use it somehow:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e5075ae9f52264fa91f793a51da3b986d82bf307.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 9, 2022, 3:01pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/2 "2022-05-09T15:01:25Z")

</div>

Because the UI wants to encourage you to use the `user.name.keyword` field (the `keyword` type of the field called `user.name`). This ensures that users do not make a mistake by choosing a field that isn't "aggregatable". Configuring the ML job through the API (or by enabling it via the Security App, which in turn uses the API) bypasses this safety check.

Based on your other recent questions, it seems like you do not understand the concepts of `mappings`, data types, and how that data is manifested in the index. May I suggest that you understand those concepts first?

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 9, 2022, 3:13pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/3 "2022-05-09T15:13:18Z")

</div>

Im definitely going to explore that at a later point. Unfortunately, im currently working on this for a school project and am very bound by the time i have. Could you maybe point me in the direction of an explanation on how to turn off this feature using the security app?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 9, 2022, 3:50pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/4 "2022-05-09T15:50:55Z")

</div>

Again, based on what you're saying on other threads, you just need to configure ML to use the fields that are actually in the data but also recognize that if you're using the UI, the UI will suggest you use the `.keyword` version of the field and that will be fine.

If you insist on using the non-keyword version of the field (i.e. `user.name` and not `user.name.keyword` then you cannot use the ML job wizards - you must use the API. But this is a futile exercise. Just use the `.keyword` version of the field.

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 9, 2022, 4:20pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/5 "2022-05-09T16:20:07Z")

</div>

The keyword function does not work though.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 9, 2022, 5:08pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/6 "2022-05-09T17:08:50Z")

</div>

You'll need to be more specific. What doesn't work? Being able to select it via the UI? The job won't run? You don't get results?

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 10, 2022, 5:17am UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/7 "2022-05-10T05:17:36Z")

</div>

It does not get results

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 10, 2022, 12:10pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/8 "2022-05-10T12:10:08Z")

</div>

Have you considered that it is possible that there are actually no anomalous examples in the data set you are using? In other words, let's say you're attempting to find a rare user name, but all of the user names in the data are consistent or routine. If that's the case, there will be no anomalies found and you will not get any "results".

[Here's an older (but still relevant) article](https://discuss.elastic.co/t/dec-4th-2018-en-ml-rarity-analysis-with-machine-learning/158979) that discusses some of the nuances around rarity analysis.

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 10, 2022, 12:50pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/9 "2022-05-10T12:50:01Z")

</div>

Yes I have most definitely considered that. But quickly rejected that idea. Because that does not make sense since the standard job does get results.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 10, 2022, 1:11pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/10 "2022-05-10T13:11:00Z")

</div>

Ok, maybe I've lost your intent given the flurry of messages across your several separate posts/threads on this discussion forum.

So, let's back up - what are you actually trying to accomplish and why isn't using the "standard job" adequate?

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 10, 2022, 2:54pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/11 "2022-05-10T14:54:00Z")

</div>

I am trying to set up a custom machine learning job that allows me to use user.name as the "by field" value for a job that recognizes anomalous users in powershell execution. I have saved a search query that filters all winlogbeat data and only shows the logs that say powershell was started. With this data i want to set up a machine learning job to detect rare user names to find anomalous occurences.

However, I cannot use the field user.name as the "by field" value. And when using the value user.name.keyword no user names get shown in the data preview. I verified the problem is not the data. So, how can i use the user.name field like in the example ml jobs in order to make my job work.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 10, 2022, 3:25pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/12 "2022-05-10T15:25:44Z")

</div>

Show me the datafeed preview output where `user.name.keyword` is used and also where `user.name` is used.

Also, I'd be curious to see your entire datafeed configuration.

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 12, 2022, 11:51am UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/13 "2022-05-12T11:51:55Z")

</div>

When using user.name.keyword:

```auto
[
  {
    "@timestamp": 1650963592372
  },
  {
    "@timestamp": 1650963592372
  },
  {
    "@timestamp": 1651475677937
  },
  {
    "@timestamp": 1651477991283
  },
  {
    "@timestamp": 1651477991283
  },
  {
    "@timestamp": 1651478109665
  },
  {
    "@timestamp": 1651478109665
  },
etc...

```

When using user.name:

```auto
[
  {
    "@timestamp": 1650963592372,
    "user.name": "flindenburg"
  },
  {
    "@timestamp": 1650963592372,
    "user.name": "flindenburg"
  },
  {
    "@timestamp": 1651475677937,
    "user.name": "msijstermans"
  },
  {
    "@timestamp": 1651477991283,
    "user.name": "avriel"
  },
  {
    "@timestamp": 1651477991283,
    "user.name": "avriel"
  },
etc...

```

So user.name gets results and user.name.test does not. So, why is it that kibana does not show user.name as an option:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7d0fb8596766c79a44117046dab44a74ee4fb845.png)

Nor does it let me add it manually because its automatically deleted.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 12, 2022, 2:29pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/14 "2022-05-12T14:29:15Z")

</div>

Thanks for the info, please also provide the output of the following:

```auto
GET metricbeat-*/_mapping

```

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 12, 2022, 2:41pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/15 "2022-05-12T14:41:20Z")

</div>

This is the output:

```auto
{ }

```

I am using winlogbeat though

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 12, 2022, 3:52pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/16 "2022-05-12T15:52:35Z")

</div>

My bad I meant:

```auto
GET winlogbeat-*/_mapping

```

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 16, 2022, 7:04am UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/17 "2022-05-16T07:04:00Z")

</div>

There seems to be too much content to post it. Is there a specific part that you are looking for that I can search for and upload here?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 16, 2022, 9:50am UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/18 "2022-05-16T09:50:10Z")

</div>

put it in a google doc, a pastebin or a gist, or whatever and link here.

---

<div class="post-metadata">

**Author:** ![anddam](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@anddam](https://discuss.elastic.co/u/anddam)\
**Post date:** [May 16, 2022, 11:37am UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/19 "2022-05-16T11:37:57Z")

</div>

> [@richcollier](#):
>
> ```auto
> GET winlogbeat-*/_mapping
> 
> ```

I hope you can reach it like this:  
[https://drive.google.com/file/d/1OQ2PZVp8PoGYLkBxpkFFXL2lPd4\_dJoC/view?usp=sharing](https://drive.google.com/file/d/1OQ2PZVp8PoGYLkBxpkFFXL2lPd4_dJoC/view?usp=sharing)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 16, 2022, 1:26pm UTC](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245/20 "2022-05-16T13:26:17Z")

</div>

That's good thanks - one more thing...please send the output of:

```auto
GET winlogbeat-*/_field_caps?fields=user*

```

[Next page](https://discuss.elastic.co/t/why-cant-i-use-user-name-as-field-in-machine-learning-job-but-the-standard-jobs-can/304245.md?page=2)
