# Adding Host fields to configuration

**URL:** <https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510>\
**Category:** Beats\
**Created:** [June 3, 2020, 10:03am UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510 "2020-06-03T10:03:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nick1](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@nick1](https://discuss.elastic.co/u/nick1)\
**Post date:** [June 3, 2020, 10:03am UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510/1 "2020-06-03T10:03:16Z")

</div>

Hi,

I'm trying to configure filebeat, winlogbeat and metricbeat to send details on their host type (OS type mainly) so I can use this field in Graylog to filter.

Host doesn't seem to be a module and the fields documented in each of the beats documentation aren't sent by default. Here is an example of the data I'm trying to send via my config to Graylog. [https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-host-processor.html](https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-host-processor.html)

My beats config looks like this at the moment:

```auto
# Needed for Graylog
fields_under_root: true
fields.collector_node_id: ${sidecar.nodeName}
fields.gl2_source_collector: ${sidecar.nodeId}

filebeat.inputs:
- input_type: log
  paths:
    - /var/log/*.log
  type: log
output.logstash:
   hosts: ["${user.GraylogHost}:5044"]
    path:
     data: /var/lib/graylog-sidecar/collectors/filebeat/data
     logs: /var/lib/graylog-sidecar/collectors/filebeat/log

```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 3, 2020, 4:27pm UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510/2 "2020-06-03T16:27:57Z")

</div>

You configuration seems incorrect. `fields_under_root` is not a global option. Also, whitespaces are off and `input_type` is not a keyword we use for anything.

Why are you using `fields_under_root`? What do you want to configure with it?

To add information about the host Filebeat runs on, you should use `add_host_metadata`. See more: [https://www.elastic.co/guide/en/beats/filebeat/master/add-host-metadata.html](https://www.elastic.co/guide/en/beats/filebeat/master/add-host-metadata.html)

I suggest you rewrite your configuration to this:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log
 
fields:
  collector_node_id: ${sidecar.nodeName}
  gl2_source_collector: ${sidecar.nodeId}

processors:
- add_host_metadata: ~

output.logstash:
   hosts: ["${user.GraylogHost}:5044"]

path.data: /var/lib/graylog-sidecar/collectors/filebeat/data
path.logs: /var/lib/graylog-sidecar/collectors/filebeat/log

```

---

<div class="post-metadata">

**Author:** ![nick1](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@nick1](https://discuss.elastic.co/u/nick1)\
**Post date:** [June 4, 2020, 7:58am UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510/3 "2020-06-04T07:58:18Z")

</div>

OK thanks, fields\_under\_root is required by Graylog.

How would this look for a Windows log?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 4, 2020, 1:42pm UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510/4 "2020-06-04T13:42:12Z")

</div>

What do you mean `fields_under_root` is required by Graylog? Does Graylog require the fields `collector_node_id` and `gl1_source_collector` on root level? If you use `fields` option the fields are added to the root.

The configuration is same regardless of the platform Filebeat is running on.

---

<div class="post-metadata">

**Author:** ![nick1](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@nick1](https://discuss.elastic.co/u/nick1)\
**Post date:** [June 4, 2020, 2:58pm UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510/5 "2020-06-04T14:58:21Z")

</div>

> **[Windows Filebeat Configuration and Graylog Sidecar | The Graylog Blog](https://www.graylog.org/post/windows-filebeat-configuration-and-graylog-sidecar)**
>
> Graylog sidecar can create and manage a centralized configuration for a filebeat agent, to gather logs from a local server that is not part of the Windows Event Channel and across all your infrastructure hosts.

  
[https://docs.graylog.org/en/3.3/pages/sidecar.html](https://docs.graylog.org/en/3.3/pages/sidecar.html)

I believe it has something to do with Graylog being able to remove the beats type prefix in the logs received (e.g. source -\> filebeat\_source).

Its part of the Graylog documentation and the example configuration they ship. As are the Filebeat and Winlogbeat configs shipped with Graylog.

The default configs shipped with Graylog are:

Linux Filebeat

```auto
# Needed for Graylog
fields_under_root: true
fields.collector_node_id: ${sidecar.nodeName}
fields.gl2_source_collector: ${sidecar.nodeId}

filebeat.inputs:
- input_type: log
  paths:
    - /var/log/*.log
  type: log
output.logstash:
   hosts: ["192.168.1.1:5044"]
path:
  data: /var/lib/graylog-sidecar/collectors/filebeat/data
  logs: /var/lib/graylog-sidecar/collectors/filebeat/log

```

Windows Filebeat

```auto
# Needed for Graylog
fields_under_root: true
fields.collector_node_id: ${sidecar.nodeName}
fields.gl2_source_collector: ${sidecar.nodeId}

output.logstash:
   hosts: ["192.168.1.1:5044"]
path:
  data: C:\Program Files\Graylog\sidecar\cache\filebeat\data
  logs: C:\Program Files\Graylog\sidecar\logs
tags:
 - windows
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - C:\logs\log.log

```

Winlogbeat

```auto
# Needed for Graylog
fields_under_root: true
fields.collector_node_id: ${sidecar.nodeName}
fields.gl2_source_collector: ${sidecar.nodeId}

output.logstash:
   hosts: ["192.168.1.1:5044"]
path:
  data: C:\Program Files\Graylog\sidecar\cache\winlogbeat\data
  logs: C:\Program Files\Graylog\sidecar\logs
tags:
 - windows
winlogbeat:
  event_logs:
   - name: Application
   - name: System
   - name: Security

```

---

<div class="post-metadata">

**Author:** ![nick1](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@nick1](https://discuss.elastic.co/u/nick1)\
**Post date:** [June 12, 2020, 3:17pm UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510/6 "2020-06-12T15:17:41Z")

</div>

Any comment on the Graylog defaults?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2020, 5:17pm UTC](https://discuss.elastic.co/t/adding-host-fields-to-configuration/235510/7 "2020-07-10T17:17:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
