# Copying field values

**URL:** <https://discuss.elastic.co/t/copying-field-values/242520>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 24, 2020, 2:13pm UTC](https://discuss.elastic.co/t/copying-field-values/242520 "2020-07-24T14:13:50Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [July 24, 2020, 2:13pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/1 "2020-07-24T14:13:50Z")

</div>

I want to copy the value of the `host.hostname` field to `host.name` or otherwise ensure that `host.name` takes this value.

I'm collecting syslog and auth data from a number of hosts on a single machine and shipping to Elastic Search from there via filebeat and the system module. The only issue is that visualizations and apps (e.g. SIEM app) default to looking at the `host.name` field for host information. The actual host from which data originates is in the files being ingested, and ends up in `host.hostname`.

I've tried using a couple of processors (copy-field, rename), but am not having much luck and getting very frustrated. Any guidance would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [July 24, 2020, 2:58pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/2 "2020-07-24T14:58:41Z")

</div>

OK! Some progress! I can overwrite the value in the `host.name` field with a value from another field using processors... I just can't figure out how to access the `host.hostname` field I guess?

As a silly test, this works:

```auto
processors:
    - drop_fields:
        fields: ["host.name"]
    - copy_fields:
        fields:
            - from: input.type
              to: host.name
        fail_on_error: false
        ignore_missing: true

```

This does not:

```auto
processors:
    - drop_fields:
        fields: ["host.name"]
    - copy_fields:
        fields:
            - from: host.hostname
              to: host.name
        fail_on_error: false
        ignore_missing: true

```

Is that the sort of problem anyone can help me to solve? Is it just a matter of figuring out how to name the field at this stage of the game?  
I see `host.hostname` in the JSON in the Discover tab, but maybe I need to call it something else in my filebeat.yml?

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [July 24, 2020, 4:42pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/3 "2020-07-24T16:42:57Z")

</div>

OK, I just cannot figure out how to access the `host.hostname` field from these processors. Is it because the field is exported via the system module?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 27, 2020, 8:43am UTC](https://discuss.elastic.co/t/copying-field-values/242520/4 "2020-07-27T08:43:30Z")

</div>

Did you try to rename the field: [https://www.elastic.co/guide/en/beats/filebeat/master/rename-fields.html](https://www.elastic.co/guide/en/beats/filebeat/master/rename-fields.html) ?

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [July 27, 2020, 3:26pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/5 "2020-07-27T15:26:49Z")

</div>

The issue seems to be that I cannot access the `host.hostname` field via processors. I have tried drop, copy\_field, and rename. I can access/change most other fields, and I can see `host.hostname` in the JSON for documents associated with the index:

```auto
...
"host": {
  "hostname": "NAME_I_CARE_ABOUT",
  "name": "NAME_I_DONT"
},
...

```

I've tried referring to both `host.hostname` and the alias `system.syslog.hostname`.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 28, 2020, 8:19am UTC](https://discuss.elastic.co/t/copying-field-values/242520/6 "2020-07-28T08:19:57Z")

</div>

Can you try with `add_host_metadata` at the beginning of the `processors` section?

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [August 4, 2020, 12:05pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/7 "2020-08-04T12:05:03Z")

</div>

Sorry for the slow response. I was away from work for a couple of days without reliable access.

Adding the `add_host_metadata` processor brings a lot of additional information about the device shipping data into my documents/JSON, but does not make the `host.hostname` field available to `rename`.

Processors now appear to read `host.hostname` as containing the value in the `host.name` field, which is not the case when I look at the JSON.

The behaviour of this processor is very unexpected:

```auto
processors:
    - add_host_metadata: ~
    - rename:
        fields:
          - from: host.hostname
            to: new_name
        fail_on_error: false
        ignore_missing: true

```

A `new_name` field will be created, containing the value of `host.name`, and both `host.hostname` and `host.name` will remain as document fields... which is to say, no `rename` operation takes place at all. I'm fairly stumped.

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [August 4, 2020, 12:29pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/8 "2020-08-04T12:29:54Z")

</div>

I feel like I'm basically trying to do exactly what @madduck proposed here:

> [@Hosts duplicated with and without fqdn](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/7):
>
> Hi Christian, glad you found something that works for you. To tie into your earlier question about doing it with winlogbeat processors thats also possible. processors: - drop\_fields: fields: ["host.name"] - copy\_fields: fields: - from: host.hostname to: host.name You will have to drop the field first because the copy\_fields function cant write into already existing fields.

That gives me some hope I'm not totally out to lunch, but I'm having a heck of a time getting my hooks into the field I'm after.

---

<div class="post-metadata">

**Author:** ![macg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/macg/32/72712_2.png) [@macg](https://discuss.elastic.co/u/macg)\
**Post date:** [August 5, 2020, 12:29pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/9 "2020-08-05T12:29:53Z")

</div>

I feel like I have a working solution. It's not perfect, but adding a processor to the ingest pipeline accomplishes the task I need.  
I added a `set` processor to the ingest pipelines for the **auth** and **syslog** data, and am now able to interact with the SIEM app sensibly and see all my hosts.

```auto
{
  "set" : {
    "field" : "host.name",
    "value" : "{{host.hostname}}"
  }
},

```

For anyone finding this thread and needing to accomplish a similar task, consider editing either the default pipelines (JSON files in `/user/share/filebeat/MODULE_NAME/SUB_MODULE/ingest/pipeline.json`) or updating exiting pipelines ([https://www.elastic.co/guide/en/elasticsearch/reference/current/put-pipeline-api.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/put-pipeline-api.html)), depending upon your set up.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2020, 2:29pm UTC](https://discuss.elastic.co/t/copying-field-values/242520/10 "2020-09-02T14:29:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
