# Best practice for enriching logs with environment names

**URL:** <https://discuss.elastic.co/t/best-practice-for-enriching-logs-with-environment-names/384655>\
**Category:** Elastic Observability\
**Tags:** fleet\
**Created:** [January 20, 2026, 4:30pm UTC](https://discuss.elastic.co/t/best-practice-for-enriching-logs-with-environment-names/384655 "2026-01-20T16:30:17Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 22, 2026, 2:49pm UTC](https://discuss.elastic.co/t/best-practice-for-enriching-logs-with-environment-names/384655/4 "2026-01-22T14:49:34Z")

</div>

Hello and welcome,

> [@curiousdba](#):
>
> This has the same issue as above, unless we can set a variable at the agent level which we can’t seem to with fleet.

In each agent policy you can add a custom field, in this custom field you can configure it to get the value from an environment variable as you can check on the answer of this similar [post](https://discuss.elastic.co/t/multi-tenant-with-fleet-and-one-single-policy-with-integrations/373019/3).

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6410920e6bb20d0637e858fd4a726f28c25a313.png)

So you could combine an environment variable and the custom field, if you want to add multiple tags, you can also combina an ingest pipeline as well.

For example, assume that you add multiple information, you can do something like this:

Create a environment varaible on the host

```auto
HOST_ENV="env1|env2|env3|envN"

```

Add this a custom field in your policy, so you will have a field with this value.

```auto
{
    "custom_field": "env1|env2|env3|envN"
}

```

You can then use the `split` processor on an ingest pipeline to split the multiple values into an array and end up with something like this:

```auto
{
    "custom_field": ["env1","env2","env3","envN"]
}

```

Then you are able to filter based on each one of the values in the array.

---

_[View the full topic](https://discuss.elastic.co/t/best-practice-for-enriching-logs-with-environment-names/384655)._
