# Add Logstash host name to JSON formatted logstream

**URL:** <https://discuss.elastic.co/t/add-logstash-host-name-to-json-formatted-logstream/140567>\
**Category:** Logstash\
**Created:** [July 18, 2018, 1:29pm UTC](https://discuss.elastic.co/t/add-logstash-host-name-to-json-formatted-logstream/140567 "2018-07-18T13:29:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hrast](https://avatars.discourse-cdn.com/v4/letter/h/35a633/32.png) [@Hrast](https://discuss.elastic.co/u/Hrast)\
**Post date:** [July 18, 2018, 1:29pm UTC](https://discuss.elastic.co/t/add-logstash-host-name-to-json-formatted-logstream/140567/1 "2018-07-18T13:29:58Z")

</div>

I've got a pipeline: JSON formatted log file -\> Filebeat -\> Logstash -\> ES. I'd like to add the Logstash host name to the document before they are sent along to ES. I took a stab at it:

default-pipeline.conf

```
input {
    beats {
        port => 5044
        codec => "json"
    }
}
filter {
  mutate {
    add_field => { "logstash_host" => "%{host}" }
  }
}

output {
  amazon_es {
    hosts => ["vpc-xxxxxx.us-east-1.es.amazonaws.com"]
    protocol => https
    codec => plain
    region => "us-east-1"
    manage_template => false
    index => "xxxxxx-logs-%{+YYYY.MM.dd}"
  }
  elasticsearch {
    hosts => ["http://xxxxxxxxx:9200"]
    index => "xxxxx-logs-%{+YYYY.MM.dd}"
    manage_template => false
  }
}

```

And what shows up in Kibana is:

`logstash_host {"name":"<hostname of system where log was sent from>"}`

So, of course, two problems:

1. The logstash\_host value isn't being converted to a JSON object
2. The hostname that is populated isn't the correct one.

My searches have not been fruitful, how would I go about doing this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 22, 2018, 6:10pm UTC](https://discuss.elastic.co/t/add-logstash-host-name-to-json-formatted-logstream/140567/2 "2018-07-22T18:10:17Z")

</div>

> ```
> logstash_host {"name":"<hostname of system where log was sent from>"}
> 
> ```

Please copy/paste from Kibana's JSON tab (visible when you expand an event). I want to see what the event _really_ looks like.

See [How can I get the logstash hostname](https://discuss.elastic.co/t/how-can-i-get-the-logstash-hostname/51771) for how to get the Logstash hostname.

---

<div class="post-metadata">

**Author:** ![Hrast](https://avatars.discourse-cdn.com/v4/letter/h/35a633/32.png) [@Hrast](https://discuss.elastic.co/u/Hrast)\
**Post date:** [July 23, 2018, 12:07am UTC](https://discuss.elastic.co/t/add-logstash-host-name-to-json-formatted-logstream/140567/3 "2018-07-23T00:07:42Z")

</div>

Here's the line from the JSON tab of a document:

`"logstash_host": "{\"name\":\"ec2-xxx-xx-x-xxxxx-xxx-10-xx-1-68\"}",`

I glanced at the logstash hostname link, and that makes sense, my only concern is does it make that socket call for every event is processed?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 24, 2018, 9:31am UTC](https://discuss.elastic.co/t/add-logstash-host-name-to-json-formatted-logstream/140567/4 "2018-07-24T09:31:20Z")

</div>

You can use a json filter to parse that JSON string, but if that's not the hostname you're interested in perhaps it doesn't matter.

> I glanced at the logstash hostname link, and that makes sense, my only concern is does it make that socket call for every event is processed?

Yes, but I'd expect it to be a cheap operation. Otherwise you should be able to fetch the hostname once when the filter initializes and reuse that value for each event. Something like this might work:

```plaintext
ruby {
  init => "
    require 'socket'
    @@hostname = Socket.gethostname
  "
  code => "event.set('host', @@hostname)"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2018, 9:31am UTC](https://discuss.elastic.co/t/add-logstash-host-name-to-json-formatted-logstream/140567/5 "2018-08-21T09:31:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
