# Add host name field

**URL:** <https://discuss.elastic.co/t/add-host-name-field/234044>\
**Category:** Logstash\
**Created:** [May 24, 2020, 1:51pm UTC](https://discuss.elastic.co/t/add-host-name-field/234044 "2020-05-24T13:51:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ahiyaz](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@ahiyaz](https://discuss.elastic.co/u/ahiyaz)\
**Post date:** [May 24, 2020, 1:51pm UTC](https://discuss.elastic.co/t/add-host-name-field/234044/1 "2020-05-24T13:51:03Z")

</div>

hi

im shipping sflow data to [Logz.io](http://Logz.io) using logstash.  
due to multi-sites architecture im trying to add hostname (agent hostname) filed to my data that  
sent from my logstash but with no success. ive tried to add it to different segments and ive tried to add tag as well.  
Does anyone have any suggestions?

thanks

attached my config and messege layout from Logzio  
/  
input {  
udp {  
port =\> 6343  
codec =\> sflow {  
}  
}  
}  
filter {

# ...

ruby {  
init =\> "require 'socket'"  
code =\> "event.set('agent.hostname', Socket.gethostname)"  
}  
mutate {  
add\_field =\> { "token" =\> "token" }  
}  
}

output {  
lumberjack {  
add\_tag =\> {"hostname" =\> "tutor"}  
hosts =\> ["listener"]  
port =\> 5006  
ssl\_certificate =\> "/usr/share/logstash/keys/TrustExternalCARoot.crt"  
codec =\> "json\_lines"  
}

# ruby {

# code =\> "event.set('agent.hostname', Socket.gethostname)"

# }

}

# 

#output {

# file {

# path =\> "/home/logstashadmin/logstash1.json"

# codec =\> line { format =\> "json"}

# }

# }/

---

<div class="post-metadata">

**Author:** ![ahiyaz](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@ahiyaz](https://discuss.elastic.co/u/ahiyaz)\
**Post date:** [May 24, 2020, 1:51pm UTC](https://discuss.elastic.co/t/add-host-name-field/234044/2 "2020-05-24T13:51:59Z")

</div>

sflow data layout (json) from my [logz.io](http://logz.io)

/{  
"\_index": "logzioCustomerIndex200524\_v2",  
"\_type": "doc",  
"_id": "AXJG7UKMEfqP4kg\_P7H_.account-123804",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"stripped": "4",  
"source\_id\_type": "0",  
"type": "lumberjack-json\_line",  
"uptime\_in\_ms": "3750559116",  
"dst\_ip": "192.168.22.34",  
"sflow\_type": "flow\_sample",  
"eth\_src": "00:09:0f:09:64:12",  
"src\_ip": "192.168.21.201",  
"protocol": "1",  
"drops": "0",  
"frame\_length": "1518",  
"sub\_agent\_id": "0",  
"ip\_version": "4",  
"@version": "1",  
"host": "172.16.0.1",  
"output\_interface": "56",  
"frame\_length\_times\_sampling\_rate": 4554000,  
"input\_interface": "45",  
"ip\_protocol": "6",  
"tags": [  
"lumberjack-json\_line-5006"  
],  
"agent\_ip": "172.16.0.1",  
"src\_port": "8001",  
"sampling\_rate": "3000",  
"sample\_pool": "430725000",  
"eth\_dst": "6c:4b:90:ac:b3:cf",  
"eth\_type": "2048",  
"@timestamp": "2020-05-24T13:44:12.109Z",  
"source\_id\_index": "56",  
"dst\_port": "64364"  
},  
"fields": {  
"@timestamp": [  
"2020-05-24T13:44:12.109Z"  
]  
},  
"sort": [  
1590327852109  
]  
}/

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [May 25, 2020, 11:23am UTC](https://discuss.elastic.co/t/add-host-name-field/234044/3 "2020-05-25T11:23:47Z")

</div>

> [@ahiyaz](#):
>
> "host": "172.16.0.1",

Usually the ""host": "172.16.0.1"," represents the machine which runs your logstash.  
Is this what you mean?

---

<div class="post-metadata">

**Author:** ![ahiyaz](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@ahiyaz](https://discuss.elastic.co/u/ahiyaz)\
**Post date:** [May 25, 2020, 1:42pm UTC](https://discuss.elastic.co/t/add-host-name-field/234044/4 "2020-05-25T13:42:02Z")

</div>

hi  
no, this address represent the network device that produce the sflow data (aka firewall)  
Im trying to add to the messages the host-name of that machine that collect the data (aka logstash)

---

<div class="post-metadata">

**Author:** ![ahiyaz](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@ahiyaz](https://discuss.elastic.co/u/ahiyaz)\
**Post date:** [May 26, 2020, 8:12am UTC](https://discuss.elastic.co/t/add-host-name-field/234044/5 "2020-05-26T08:12:46Z")

</div>

the issue was that when loading logstash using systemctl the demon didn't pull the the configuration from the \*.conf file under /etc/logstash/conf.d/  
only when loading via cli this configuration pulls.

ive added a new filed under my input  
/ add\_field =\> {  
"agent.hostname" =\> "sflow\_agent"  
/

and it shown now in my kibana dashboard.

regarding the \*.conf issue.  
ive verified that my pipeline.yml is pointing to this config directory  
/

- pipeline.id: main  
path.config: "/etc/logstash/conf.d/\*.conf"  
/

and that my logstash.yml the main pipeline is enabled  
/  
pipeline.id: main  
/

permission wise all files owned by root  
but i installed my logstash as root (sudo bash)  
ive tried to execute "chmod 644 \*" in my directories but it didn't help

any idea how to solved it?  
thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2020, 8:15am UTC](https://discuss.elastic.co/t/add-host-name-field/234044/6 "2020-06-23T08:15:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
