# CEF module parsing, agent.name and agent.hostname are incorrectly set

**URL:** <https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [May 25, 2020, 6:37am UTC](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084 "2020-05-25T06:37:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![undelete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/undelete/32/24186_2.png) [@undelete](https://discuss.elastic.co/u/undelete)\
**Post date:** [May 25, 2020, 6:37am UTC](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084/1 "2020-05-25T06:37:57Z")

</div>

Hi, Im using the Filebeat 7.6.0 to parse CEF logs from our ArcSight SmartConnector. I've noticed that agent.hostname and agent.name is incorrectly set. Agent.name should not be the hostname of the host where the SmartConnector is running, but the actual name that is configured for the SmartConnector. And agent.hostname is reporting the hostname of the host that actually created the log, the original sender, which is incorrect. agent.hostname should be the hostname of the host that is running the SmartConnector (same as cef.extensions.agentHostName).

Anyone else noticed this?

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [May 29, 2020, 12:29am UTC](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084/2 "2020-05-29T00:29:40Z")

</div>

A short question here:  
Do you use CEF module  
[https://www.elastic.co/guide/en/beats/filebeat/7.6/filebeat-module-cef.html](https://www.elastic.co/guide/en/beats/filebeat/7.6/filebeat-module-cef.html)  
or CEF processor?  
[https://www.elastic.co/guide/en/beats/filebeat/7.6/processor-decode-cef.html](https://www.elastic.co/guide/en/beats/filebeat/7.6/processor-decode-cef.html)

Could you provide a short extract of config?

Because normally I would assume that Arcsight agent hostname would be in field `cef.extensions.agentHostName`  
[https://www.elastic.co/guide/en/beats/filebeat/7.6/exported-fields-cef.html](https://www.elastic.co/guide/en/beats/filebeat/7.6/exported-fields-cef.html)

If you want to have agent.name this holds the name of where the filebeat shipper is at home:  
[https://www.elastic.co/guide/en/beats/filebeat/7.6/configuration-general-options.html#\_name](https://www.elastic.co/guide/en/beats/filebeat/7.6/configuration-general-options.html#_name)

What happens in actual version 7.7 of filebeat?

---

<div class="post-metadata">

**Author:** ![undelete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/undelete/32/24186_2.png) [@undelete](https://discuss.elastic.co/u/undelete)\
**Post date:** [May 29, 2020, 8:37am UTC](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084/3 "2020-05-29T08:37:54Z")

</div>

Hi, thanks for replying. I'm using the cef module in filebeat.

Ok, so agent is for Beats, got it.

That is true that cef.extensions.agentHostName is populated, but where is cef.extensions.agentName in that case? The information is necessary since a host can have multiple ArcSight SmartConnectors and the name is the only way to distinguish them from one another.

Edit: I see, this is a limitation of the CEF standard, that's why I'm missing this information.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 1, 2020, 10:51am UTC](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084/4 "2020-06-01T10:51:54Z")

</div>

Unfortunately CEF defines more the how you transport fields but it's not 100% consistent over the vendors.

I had a look into the Arcsight CEF implementation here:  
[https://community.microfocus.com/t5/ArcSight-Connectors/ArcSight-Common-Event-Format-CEF-Implementation-Standard/ta-p/1645557?attachment-id=68077](https://community.microfocus.com/t5/ArcSight-Connectors/ArcSight-Common-Event-Format-CEF-Implementation-Standard/ta-p/1645557?attachment-id=68077)

And it looks like you have an `aid` field, which should be quite similar to an `agentName` field. So my question is, do you have an `aid` (Agent id) field?

Because then you could use this on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2020, 10:51am UTC](https://discuss.elastic.co/t/cef-module-parsing-agent-name-and-agent-hostname-are-incorrectly-set/234084/5 "2020-06-29T10:51:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
