# Can host.name in Entra ID Entity Analytics be lowercased and domain appended?

**URL:** <https://discuss.elastic.co/t/can-host-name-in-entra-id-entity-analytics-be-lowercased-and-domain-appended/358437>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-security\
**Created:** [April 29, 2024, 2:26pm UTC](https://discuss.elastic.co/t/can-host-name-in-entra-id-entity-analytics-be-lowercased-and-domain-appended/358437 "2024-04-29T14:26:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [April 29, 2024, 2:26pm UTC](https://discuss.elastic.co/t/can-host-name-in-entra-id-entity-analytics-be-lowercased-and-domain-appended/358437/1 "2024-04-29T14:26:09Z")

</div>

Hello,

I've activated Entra ID Entity Analytics integration. Very nice data sets, but I'm having the same issues I've been having for year in different datasets (of which most of them have been solved or mitigated). The `host.name` field of the devices is not lowercase fqdn. Now the issue is that the Entra ID data doesn't have an domain in the data, so although it might be possible to lowercase, appending the domain might be more difficult, as Entra ID contains all kinds of devices, some of which are not ServerAd. I'm thinking about editing the @custom pipeline logs-entityanalytics\_entra\_id.device@custom and adding it myself.

But I might not be the only one with a larger environment with multiple domains in need to a unique and correlatable host.name id.

So any chance an option can be added so the host.name can get lowercased and a custom domain appended? That way we can correlate this data with network datasets, vulnerability datasets and more..

Willem

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 18, 2024, 7:51pm UTC](https://discuss.elastic.co/t/can-host-name-in-entra-id-entity-analytics-be-lowercased-and-domain-appended/358437/2 "2024-05-18T19:51:23Z")

</div>

Hello,

So I fixed it like this for now..

```auto
PUT _ingest/pipeline/logs-entityanalytics_entra_id.device@custom
{
  "processors": [
    {
      "script": {
        "if": "ctx.entityanalytics_entra_id?.device?.trust_type == 'ServerAd' || ctx.entityanalytics_entra_id?.device?.trust_type == 'AzureAd'",
        "lang": "painless",
        "source": "ctx.host.name = ctx.host.name + '.yourdomain.com'"
      }
    },
    {
      "lowercase": {
        "field": "host.name"
      }
    },
    {
      "set": {
        "field": "host.hostname",
        "value": "{{host.name}}"
      }
    }
  ],
  "on_failure": [
    {
      "append": {
        "field": "tags",
        "value": [
          "failed_custom_entra_id_device"
        ]
      }
    }
  ]
}

```

Unfortunately I was surprised `host.hostname` is not in the provided mapping... ☹

Guess I'll need to add that too in the @cutom mapping..

WillemD
