# Why does client.version field does not exist?

**URL:** https://discuss.elastic.co/t/why-does-client-version-field-does-not-exist/345896
**Category:** Elasticsearch
**Tags:** ecs-elastic-common-schema
**Created:** [October 27, 2023, 8:47am UTC](https://discuss.elastic.co/t/why-does-client-version-field-does-not-exist/345896 "2023-10-27T08:47:10Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![babs](https://avatars.discourse-cdn.com/v4/letter/b/cdc98d/32.png) [@babs](https://discuss.elastic.co/u/babs)
#### Post date: [October 27, 2023, 8:47am UTC](https://discuss.elastic.co/t/why-does-client-version-field-does-not-exist/345896/1 "2023-10-27T08:47:10Z")

</div>

Hello,

I wonder why the `client.version` field does not exist in the ECS ?  
Does it have to be a custom field ?

There is a `agent.version`, a `service.version`, but `client.version` does not exist.

Edit: I see that `server.version` and `source.version` do not exist either, it seems related (to the thing I don't get 😅).

Usecase: I have to process vpn server logs, the client version appears in the logs, and I want to store it. I can obviously make a custom `vpn.client.version` but I thought there was a more generic approach.

TY in advance for your response,  
Babs

---

<div class="post-metadata">

### Author: ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)
#### Post date: [October 27, 2023, 1:55pm UTC](https://discuss.elastic.co/t/why-does-client-version-field-does-not-exist/345896/2 "2023-10-27T13:55:27Z")

</div>

Hi, @babs!

In ECS the `client.*` fields describes the initiator of a network connection between a client/server. The type of software client you're describing is often a good candidate to use the `service.*` fields.

ECS defines `service.origin.version` as a [nesting](https://www.elastic.co/guide/en/ecs/current/ecs-service.html#ecs-service-nestings) of `service.*`, and I see the field being a good fit for your use case.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 24, 2023, 1:56pm UTC](https://discuss.elastic.co/t/why-does-client-version-field-does-not-exist/345896/3 "2023-11-24T13:56:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
