# Beat.hostname & beat.name values

**URL:** <https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [May 8, 2018, 2:56am UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925 "2018-05-08T02:56:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ecc256](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ecc256/32/59815_2.png) [@ecc256](https://discuss.elastic.co/u/ecc256)\
**Post date:** [May 8, 2018, 2:56am UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/1 "2018-05-08T02:56:54Z")

</div>

Elastic search shows events posted by my beat with following values in beat.\* fields:  
`beat.hostname hostname`  
`beat.name hostname`  
`beat.version 7.0.0-alpha1`  
I guess, this is due to [beat.go](https://github.com/elastic/beats/blob/master/libbeat/cmd/instance/beat.go#L180) code.  
What would be the easiest way to have `beat.name` show `beat.Info.Beat` (i.e. "my beat name")?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 8, 2018, 9:31am UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/2 "2018-05-08T09:31:56Z")

</div>

The value in `beat.name` is a custom user-defined name. It's supposed to be changed by operators to identify a machine the data come from.  
Your beats name is published at least via `@metadata`. Users integration beats with Logstash, normally use the `@metadata` fields, so to generate the same index names for example.

The `name` setting overwrite `beat.name`.

---

<div class="post-metadata">

**Author:** ![ecc256](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ecc256/32/59815_2.png) [@ecc256](https://discuss.elastic.co/u/ecc256)\
**Post date:** [May 8, 2018, 3:33pm UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/3 "2018-05-08T15:33:38Z")

</div>

> [@steffens](#):
>
> The value in beat.name is a custom user-defined name. It's supposed to be changed by operators to identify a machine the data come from.

Ok.  
What is the purpose of `beat.hostname` then?

> [@steffens](#):
>
> Your beats name is published at least via @metadata.

That’s all I see it in Elasticsearch:  
`@timestamp May 8th 2018, 0:00:00.000`  
`t _id 100000001`  
`t _index test-7.0.0-alpha1-2018.05.08`  
`# _score - `  
`t _type doc`  
`t beat.hostname hostname`  
`t beat.name hostname`  
`t beat.version 7.0.0-alpha1`  
`# id 100,000,001`  
Do I have to add it manually?

> [@steffens](#):
>
> The name setting overwrite beat.name.

May I have an example, please?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 8, 2018, 3:56pm UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/4 "2018-05-08T15:56:01Z")

</div>

> > The name setting overwrite beat.name.
> 
> May I have an example, please?

Adding this to your config file:

```auto
name: abc

```

will give you:

```auto
|@timestamp|May 8th 2018, 0:00:00.000|
|---|---|
|t _id|100000001|
|t _index|test-7.0.0-alpha1-2018.05.08|
|# _score|-|
|t _type|doc|
|t beat.hostname|hostname|
|t beat.name|abc|
|t beat.version|7.0.0-alpha1|
|# id|100,000,001|

```

The hostname can not be changed and is only the hostname (not the FQDN). For users running multiple beats one the same host (indexing into the same index) or having a setup with machines having the same hostname (but with different domain name), the `name` setting adds some more filtering capabilities.

---

<div class="post-metadata">

**Author:** ![ecc256](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ecc256/32/59815_2.png) [@ecc256](https://discuss.elastic.co/u/ecc256)\
**Post date:** [May 8, 2018, 4:30pm UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/5 "2018-05-08T16:30:30Z")

</div>

> [@steffens](#):
>
> Adding this to your config file:

I’ve seen [beat.go](https://github.com/elastic/beats/blob/master/libbeat/cmd/instance/beat.go#L80) code. I tried with [testbeat](https://gist.github.com/ecc256/b5b2c0fd7fa10f7a99da8e8e7bd36cab). Neither  
`test:`  
` name: abc`  
nor  
`test:`  
` name: "abc"`  
works in `test.yml`.  
Did I do it wrong?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 10, 2018, 11:40am UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/6 "2018-05-10T11:40:13Z")

</div>

It's a global setting, no indentation required. All libbeat settings are available in the [config.reference.yml](https://github.com/elastic/beats/blob/master/libbeat/_meta/config.reference.yml). When running `make update`, the beats local `<beatname>/_meta/config.yml` and `<beatname>_meta/config.reference.yml` are concatenated with the `github.com/elastic/beats/libbeat/_meta/config.<>.yml` files.

---

<div class="post-metadata">

**Author:** ![ecc256](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ecc256/32/59815_2.png) [@ecc256](https://discuss.elastic.co/u/ecc256)\
**Post date:** [May 14, 2018, 5:42pm UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/7 "2018-05-14T17:42:23Z")

</div>

> [@steffens](#):
>
> It's a global setting, no indentation required. All libbeat settings are available in the config.reference.yml

Worked like a charm!  
Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 5:42pm UTC](https://discuss.elastic.co/t/beat-hostname-beat-name-values/130925/8 "2018-06-11T17:42:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
