# Can I change the primary key for identifying hosts in the SIEM app?

**URL:** <https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372>\
**Category:** SIEM\
**Created:** [July 23, 2020, 4:32pm UTC](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372 "2020-07-23T16:32:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [July 23, 2020, 4:32pm UTC](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372/1 "2020-07-23T16:32:38Z")

</div>

I'm shipping logs from a number of hosts via a single filebeat running on a collector. As a result, the default primary key used by the SIEM app `host.name` is not very useful to me. `host.hostname` would work a lot better. Can I change the primary key for identifying hosts in the SIEM app? Can I alternatively add/remove/change lines in my `filebeat.yml` to remap fields so that `host.name` will contain the same data as `host.hostname`?

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [July 23, 2020, 5:38pm UTC](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372/2 "2020-07-23T17:38:42Z")

</div>

Could I maybe work around this problem by using the `copy_fields` processor? I've tried something like this:

```auto
processors:
    - copy_fields:
        fields:
            - from: host.hostname
              to: host.name
        fail_on_error: false
        ignore_missing: true

```

But, I don't seem to get the desired result...

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [July 27, 2020, 10:27pm UTC](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372/3 "2020-07-27T22:27:05Z")

</div>

I haven't done this before as I particularly enjoy using `host.name` but this might be helpful as it looks like someone else has done this before:

> [@Hosts duplicated with and without fqdn](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/7):
>
> Hi Christian, glad you found something that works for you. To tie into your earlier question about doing it with winlogbeat processors thats also possible. processors: - drop\_fields: fields: ["host.name"] - copy\_fields: fields: - from: host.hostname to: host.name You will have to drop the field first because the copy\_fields function cant write into already existing fields.

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [August 4, 2020, 12:12pm UTC](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372/4 "2020-08-04T12:12:51Z")

</div>

Sorry for the slow response. I was without reliable access for a couple of days. I'm interested in the approach of declaring a new ingest pipeline, but could use a little direction in that regard. I've been working on dropping/copying/renaming fields as a parallel solution without much luck. I cannot access `host.hostname` from my processors for some reason.

> [@Copying field values](https://discuss.elastic.co/t/copying-field-values/242520/7):
>
> Sorry for the slow response. I was away from work for a couple of days without reliable access. Adding the add\_host\_metadata processor brings a lot of additional information about the device shipping data into my documents/JSON, but does not make the host.hostname field available to rename. Processors now appear to read host.hostname as containing the value in the host.name field, which is not the case when I look at the JSON. The behaviour of this processor is very unexpected: processors: …

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2020, 12:12pm UTC](https://discuss.elastic.co/t/can-i-change-the-primary-key-for-identifying-hosts-in-the-siem-app/242372/5 "2020-09-01T12:12:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
