# \#ecs-elastic-common-schema

**URL:** https://discuss.elastic.co/tag/ecs-elastic-common-schema/26.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Unifi Syslog ECS Mapping](https://discuss.elastic.co/t/unifi-syslog-ecs-mapping/386089)

<div class="topic-metadata">

**Author:** [@AxelZoldik](https://discuss.elastic.co/u/AxelZoldik)\
**Replies:** 0\
**Last updated:** [April 29, 2026, 7:24am UTC](https://discuss.elastic.co/t/unifi-syslog-ecs-mapping/386089 "2026-04-29T07:24:33Z")

</div>

Hello everyone I hope you are all doing well, I'm wondering if someone has already a pipeline logstash for mapping Unifi firewall logs to ECS, It might be worth to create an integration directly in Kibana if I'm not al…

---

## [Problems using ecs](https://discuss.elastic.co/t/problems-using-ecs/381340)

<div class="topic-metadata">

**Author:** [@Ruslan\_Hafizov](https://discuss.elastic.co/u/Ruslan_Hafizov)\
**Replies:** 1\
**Last updated:** [August 29, 2025, 6:35pm UTC](https://discuss.elastic.co/t/problems-using-ecs/381340 "2025-08-29T18:35:48Z")

</div>

I try to use ecs to standardize various logs from different applications. I don't always manage to find a field that suits the situation, especially when it comes to user authorization/authentication. I would like to pro…

---

## [Where do OpenTelemetry logs end up in Elasticsearch](https://discuss.elastic.co/t/where-do-opentelemetry-logs-end-up-in-elasticsearch/379554)

<div class="topic-metadata">

**Author:** [@flalar](https://discuss.elastic.co/u/flalar)\
**Replies:** 0\
**Last updated:** [June 27, 2025, 7:35am UTC](https://discuss.elastic.co/t/where-do-opentelemetry-logs-end-up-in-elasticsearch/379554 "2025-06-27T07:35:45Z")

</div>

Hi all, I'm currently experimenting with using OpenTelemetry to send logs into Elasticsearch and trying to understand exactly where those logs end up once they arrive. So far, I see that metrics and traces follow somew…

---

## [Elastic Common Schema For Network Devices/SNMP](https://discuss.elastic.co/t/elastic-common-schema-for-network-devices-snmp/379168)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [June 13, 2025, 4:41pm UTC](https://discuss.elastic.co/t/elastic-common-schema-for-network-devices-snmp/379168 "2025-06-13T16:41:31Z")

</div>

Hello, Does elastic have standardized fields for network devices? If not, is there plans for it? Thanks, E

---

## [Logstash is not fully using index template](https://discuss.elastic.co/t/logstash-is-not-fully-using-index-template/376042)

<div class="topic-metadata">

**Author:** [@Jesselastic](https://discuss.elastic.co/u/Jesselastic)\
**Replies:** 1\
**Last updated:** [May 22, 2025, 10:56pm UTC](https://discuss.elastic.co/t/logstash-is-not-fully-using-index-template/376042 "2025-05-22T22:56:41Z")

</div>

I have syslog docs coming through logstash and everything is mapping to the correct field names. The index template that has a pattern matching the logs from logstash correctly creates datastreams and ilm is working gre…

---

## [Filling Metadata with Elastic.Extensions.Logging](https://discuss.elastic.co/t/filling-metadata-with-elastic-extensions-logging/377810)

<div class="topic-metadata">

**Author:** [@vicariouskp](https://discuss.elastic.co/u/vicariouskp)\
**Replies:** 0\
**Last updated:** [May 5, 2025, 11:20am UTC](https://discuss.elastic.co/t/filling-metadata-with-elastic-extensions-logging/377810 "2025-05-05T11:20:32Z")

</div>

Hello, I'm trying to use Elastic.Extensions.Logging nuget in c# application and I don't know how to add Metadata property. How can I for example log some custom made class passed as an one of the args object in the Logge…

---

## [\`WriteTo\` JSON formatter](https://discuss.elastic.co/t/writeto-json-formatter/377362)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [April 23, 2025, 12:03pm UTC](https://discuss.elastic.co/t/writeto-json-formatter/377362 "2025-04-23T12:03:04Z")

</div>

I use GitHub - denis-peshkov/Serilog.Enrichers.HttpContext: Enriches Serilog events with client IP, Correlation Id, RequestBody, RequestQuery, HTTP request headers and information of the memory usage. to extract http h…

---

## [Valid values for service.state](https://discuss.elastic.co/t/valid-values-for-service-state/373766)

<div class="topic-metadata">

**Author:** [@kelunik](https://discuss.elastic.co/u/kelunik)\
**Replies:** 1\
**Last updated:** [January 28, 2025, 5:07pm UTC](https://discuss.elastic.co/t/valid-values-for-service-state/373766 "2025-01-28T17:07:16Z")

</div>

I have (long-running) processes that have a starting, running and shutdown phase. I want to filter logs to only show the running phase. I looked at ECS and found service.state as a field that might be suitable, however, …

---

## [How to stop Filebeat from shipping incorrect JSON to Elastic?](https://discuss.elastic.co/t/how-to-stop-filebeat-from-shipping-incorrect-json-to-elastic/369162)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 2\
**Last updated:** [November 13, 2024, 3:46pm UTC](https://discuss.elastic.co/t/how-to-stop-filebeat-from-shipping-incorrect-json-to-elastic/369162 "2024-11-13T15:46:14Z")

</div>

Hi, Our applications emit logs in ECS format, a log entry per line. In Filebeat config we have a parser defined: parsers: - ndjson: target: '' expand\_keys: true overwrite\_keys: true add\_error\_…

---

## [How to structure logging to get the most out of built in ML](https://discuss.elastic.co/t/how-to-structure-logging-to-get-the-most-out-of-built-in-ml/370009)

<div class="topic-metadata">

**Author:** [@flalar](https://discuss.elastic.co/u/flalar)\
**Replies:** 0\
**Last updated:** [November 4, 2024, 1:13pm UTC](https://discuss.elastic.co/t/how-to-structure-logging-to-get-the-most-out-of-built-in-ml/370009 "2024-11-04T13:13:36Z")

</div>

We’re looking for best practices for structuring our application log streams to utilize the built in ML capacities in Observabilty. Today we log everything from 30 different services with Serilog to the same datastream i…

---

## [Observability Overview - Logs not shown as log source](https://discuss.elastic.co/t/observability-overview-logs-not-shown-as-log-source/368183)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 23\
**Last updated:** [October 17, 2024, 12:18pm UTC](https://discuss.elastic.co/t/observability-overview-logs-not-shown-as-log-source/368183 "2024-10-17T12:18:55Z")

</div>

Hi Running Kibana version: 8.14.3 I'm trying to show my "log sources" via the Observability Overview screen. It contains a via view: Log Events \> Logs rate per minute I assume this is the required config: Although I…

---

## [Is it possible to do ecs trace logging with rust?](https://discuss.elastic.co/t/is-it-possible-to-do-ecs-trace-logging-with-rust/368420)

<div class="topic-metadata">

**Author:** [@Mang-Joo](https://discuss.elastic.co/u/Mang-Joo)\
**Replies:** 0\
**Last updated:** [October 8, 2024, 8:28am UTC](https://discuss.elastic.co/t/is-it-possible-to-do-ecs-trace-logging-with-rust/368420 "2024-10-08T08:28:12Z")

</div>

Hello I want to create a single trace by integrating a Rust project with a Java Project and API. However, there is no library officially supported by Elasticsearch for Rust. (e.g., for Java: logback-ecs-encoder) Is the…

---

## [Mapping Apache HTTPD log output to ECS Schema?](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082)

<div class="topic-metadata">

**Author:** [@greenbeans](https://discuss.elastic.co/u/greenbeans)\
**Replies:** 3\
**Last updated:** [July 14, 2024, 1:40am UTC](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082 "2024-07-14T01:40:54Z")

</div>

Has anyone mapped the various Apache HTTPD logging variables/output to the Elastic Common Schema? Seems like it should be pretty straightforward but tedious, and really useful. If you've done any of this, please share! …

---

## [Elastic Common Schema Jobss Logs Implementation](https://discuss.elastic.co/t/elastic-common-schema-jobss-logs-implementation/362002)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [June 25, 2024, 9:38am UTC](https://discuss.elastic.co/t/elastic-common-schema-jobss-logs-implementation/362002 "2024-06-25T09:38:57Z")

</div>

Hello i am injesting jboss logs to the elastic have some of the fields to grok, but i want to use the ELastic Common schema to store those here is my log: 2024-06-25 11:59:50,358 ERROR \[stderr\] (default task-100) at o…

---

## [Import JSON Schema for ECS Events](https://discuss.elastic.co/t/import-json-schema-for-ecs-events/358883)

<div class="topic-metadata">

**Author:** [@vances](https://discuss.elastic.co/u/vances)\
**Replies:** 5\
**Last updated:** [May 9, 2024, 5:50pm UTC](https://discuss.elastic.co/t/import-json-schema-for-ecs-events/358883 "2024-05-09T17:50:03Z")

</div>

Having written meticulous JSON Schema files, using the Elastic Common Schema (ECS) guidelines, describing our events I am surprised to find no obvious way to import and use those schemas in Elastic Stack. Am I missing s…

---

## [ECS RFC process questions](https://discuss.elastic.co/t/ecs-rfc-process-questions/356576)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 4\
**Last updated:** [April 2, 2024, 2:11pm UTC](https://discuss.elastic.co/t/ecs-rfc-process-questions/356576 "2024-04-02T14:11:53Z")

</div>

The RFC process includes at least one step that I'm not sure how to participate in, highlighted here: Create a new RFC document from the RFC template (described below) Fill in the details for your strawperson Open a P…

---

## [Field name limitations](https://discuss.elastic.co/t/field-name-limitations/355522)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 2\
**Last updated:** [March 18, 2024, 7:08pm UTC](https://discuss.elastic.co/t/field-name-limitations/355522 "2024-03-18T19:08:34Z")

</div>

I'm wondering what the limitations are for field names. I've seen some crazy things in our dynamic mappings, so I bet Lucene and ES are super flexible. For example, can you use a leading underscore? I notice that ES m…

---

## [Log.original field lost with upgrade 8.6.1 from 1.5.3](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363)

<div class="topic-metadata">

**Author:** [@ridvandev](https://discuss.elastic.co/u/ridvandev)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 11:25pm UTC](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363 "2023-11-30T23:25:06Z")

</div>

We used to use the log.original field a lot for our searches in Kibana, but since the upgrade of Elastic.CommonSchema.Nlog package, I can't seem to find this field anymore. Also, it looks like the log template we depend …

---

## [Why does client.version field does not exist?](https://discuss.elastic.co/t/why-does-client-version-field-does-not-exist/345896)

<div class="topic-metadata">

**Author:** [@babs](https://discuss.elastic.co/u/babs)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 1:55pm UTC](https://discuss.elastic.co/t/why-does-client-version-field-does-not-exist/345896 "2023-10-27T13:55:27Z")

</div>

Hello, I wonder why the client.version field does not exist in the ECS ? Does it have to be a custom field ? There is a agent.version, a service.version, but client.version does not exist. Edit: I see that server.ver…

---

## [Elastic Common Schema support for Opensearch](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452)

<div class="topic-metadata">

**Author:** [@q3uxlyn](https://discuss.elastic.co/u/q3uxlyn)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:22pm UTC](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452 "2023-10-05T19:22:19Z")

</div>

Hello! Have you plans about adding OpenSearch support to Elastic Common Schema? Cause of OpenSearch has different field types than Elasticsearch we can't easily use ECS. I want to be able to keep the schemas up to date…

---

## [Geo fields at root?](https://discuss.elastic.co/t/geo-fields-at-root/341307)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 12:58am UTC](https://discuss.elastic.co/t/geo-fields-at-root/341307 "2023-08-22T00:58:17Z")

</div>

ECS geo docs say: The geo fields are expected to be nested at: client.geo destination.geo host.geo server.geo ... Note also that the geo fields are not expected to be used directly at the root of the events. I was …

---

## [A good place for "state of being a canary" field](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 11:21pm UTC](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690 "2023-08-21T23:21:14Z")

</div>

Where do you think is a good place to indicate that a log message is from a canary? orchestration.\* doesn't seem appropriate. Maybe something in the upcoming node field set? (Where do I find information about that?) I…

---

## [\`host.name\` and \`host.hostname\`](https://discuss.elastic.co/t/host-name-and-host-hostname/339742)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 9:24pm UTC](https://discuss.elastic.co/t/host-name-and-host-hostname/339742 "2023-08-03T21:24:27Z")

</div>

What kind of values are folks using for host.name and host.hostname? Basically I think ECS is encouraging FQDN in host.name and short name in host.hostname?

---

## [ECS Format and Index Mappings](https://discuss.elastic.co/t/ecs-format-and-index-mappings/336740)

<div class="topic-metadata">

**Author:** [@lxk3](https://discuss.elastic.co/u/lxk3)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 1:59pm UTC](https://discuss.elastic.co/t/ecs-format-and-index-mappings/336740 "2023-06-23T13:59:57Z")

</div>

Hello there, we want to use the ECS log format for our new applications. We already use datastreams with index templates and predefined mappings and I was wondering if we need to write a new mapping for ECS or if there …

---

## [How to describe multiple users in ECS](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448)

<div class="topic-metadata">

**Author:** [@srilumpa](https://discuss.elastic.co/u/srilumpa)\
**Replies:** 4\
**Last updated:** [June 13, 2023, 7:29am UTC](https://discuss.elastic.co/t/how-to-describe-multiple-users-in-ecs/335448 "2023-06-13T07:29:52Z")

</div>

Hello, I have a use case that is not described in the Elastic ECS documentation and I am looking for best practices on how to handle this. So, basically, I have an application where an app admin can change multiple use…

---

## [How to queue ECS formatted logs through RabbitMQ](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105)

<div class="topic-metadata">

**Author:** [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Replies:** 3\
**Last updated:** [June 7, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-queue-ecs-formatted-logs-through-rabbitmq/335105 "2023-06-07T13:48:16Z")

</div>

Hello all, Our logging infrastructure is the following: log shippers -\> logstash -\> rabbitmq -\> logstash -\> elasticsearch I am trying to start using ECS, have the template set up. However, when the first logstash plac…

---

## [Error when attempting to create component template using the ECS generator](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004)

<div class="topic-metadata">

**Author:** [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 6:40pm UTC](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004 "2023-06-04T18:40:56Z")

</div>

Hello all, I am using the ECS mapping template generator to create the relevant components so we can start using the ECS fields. I cloned GitHub - elastic/ecs: Elastic Common Schema and generated essentially the default…

---

## [GeoIP filter missing some ECS fields](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 7\
**Last updated:** [May 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339 "2023-05-17T05:18:00Z")

</div>

I am using the GeoIP Logstash filter and it seems to not have some desired fields for example \[mmdb\]\[isp\]. Overall it has no as or mmdb fields, as well as some other random fields. It does have all the geo fields however…

---

## [Logs and no-index fields](https://discuss.elastic.co/t/logs-and-no-index-fields/331009)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 4:13pm UTC](https://discuss.elastic.co/t/logs-and-no-index-fields/331009 "2023-05-01T16:13:22Z")

</div>

Has anyone implemented a no-indexing strategy for their logs customers? Meaning, I’d like to allow my customers to insert arbitrary data/structure, but not consume from the finite field count resource, so I want to map …

---

## [Azure Logs Integration with ECS logs](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041)

<div class="topic-metadata">

**Author:** [@CrystalDesignDR](https://discuss.elastic.co/u/CrystalDesignDR)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 10:03am UTC](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041 "2023-04-28T10:03:24Z")

</div>

Hi, we are running Elastic Cloud and want to add Application Logs to it with Elastic Agent, these logs need to be correlated with out APM traces. We are running the Elastic Azure Logs Integration with the Elastic Agent…

[Next page](https://discuss.elastic.co/tag/ecs-elastic-common-schema/26.md?match_all_tags=true&page=1&tags%5B%5D=ecs-elastic-common-schema)
