I want to copy the value of the
host.hostname field to
host.name or otherwise ensure that
host.name takes this value.
I'm collecting syslog and auth data from a number of hosts on a single machine and shipping to Elastic Search from there via filebeat and the system module. The only issue is that visualizations and apps (e.g. SIEM app) default to looking at the
host.name field for host information. The actual host from which data originates is in the files being ingested, and ends up in
I've tried using a couple of processors (copy-field, rename), but am not having much luck and getting very frustrated. Any guidance would be greatly appreciated.