# Dash character in hostnames and filesystem mount points

**URL:** https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790
**Category:** Beats
**Created:** [December 9, 2015, 7:45pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790 "2015-12-09T19:45:53Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)
#### Post date: [December 9, 2015, 7:45pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/1 "2015-12-09T19:45:53Z")

</div>

topbeat dashboard seems not to like hostnames with "-" character or in filesystem mount points, there's a warning about "-" not being supported because those fields are analyzed fields. Is there a way to change the topbeat index mapping to fix this?

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 9, 2015, 7:58pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/2 "2015-12-09T19:58:31Z")

</div>

Did you use the topbeat template? [https://github.com/elastic/topbeat/blob/master/etc/topbeat.template.json](https://github.com/elastic/topbeat/blob/master/etc/topbeat.template.json)

---

<div class="post-metadata">

### Author: ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)
#### Post date: [December 9, 2015, 8:17pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/3 "2015-12-09T20:17:05Z")

</div>

I did load the topbeat template into ES, wondering if might be because I'm using logstash-YYYY-MM-DD index ... does topbeat need to insert directly into ES ? Or can it go through logstash? I ran into other issues (geo ip) using the default "%{[@metadata][beat]}-%{+YYYY.MM.dd}" index, had to use the logstash- index to get geo working.

current logstash output setup :

```
output {
  elasticsearch {
    hosts => "localhost:9200"
   sniffing => false
   manage_template => true
index => "logstash-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
 } 
}
```

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 9, 2015, 9:33pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/4 "2015-12-09T21:33:50Z")

</div>

Topbeat data can go through Logstash. The question is to which index you applied the template. Topbeat-\* or Logstash-\*?

---

<div class="post-metadata">

### Author: ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)
#### Post date: [December 9, 2015, 10:23pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/5 "2015-12-09T22:23:31Z")

</div>

Tried loading to both, I think the issue is my LS is set to send all output to the logstash- index, while the dashboard and topbeat .json index templates are configured to use topbeat-\* ,

I configured this setup on a another system using LS -\> ES with topbeat sending into LS locally and it all works fine. (using default index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}" LS output to ES)

Seems the issue is where I configured LS to send all output to logstash-\* index, that breaks topbeat (since the index templates for beats dashboard and topbeat don't specify logstash-\* as the index), but I need logstash-\*for geo with filebeat. I imagine there's an easy fix somewhere, just have some confusion about which index to use. I know geo doesn't have the correct type mappings (float or numbers instead of geo point) when using the default index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}" setup in LS output

---

<div class="post-metadata">

### Author: ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)
#### Post date: [December 10, 2015, 3:44am UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/6 "2015-12-10T03:44:49Z")

</div>

maybe answering my own question here ... wondering if a simple if condition in my LS config could direct all topbeat data into the topbeat-YYYY.MM.DD index, then all log based data (for geo, etc.) would be directed into the logstash-YYYY.MM.DD index.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 10, 2015, 8:48am UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/7 "2015-12-10T08:48:20Z")

</div>

I think we are on the right way. A few points here:

- I highly recommend to use different indices for each beat. You can easily write a filter in LS to send each event to the correct index for example based on the type which is sent by each beat.
- As you correctly mentioned, there is no geo in the default template for filebeat, as there is no "geo" value before going to LS. The easiest solution here would be to add the field you use for geo to the template and then apply it: [https://github.com/elastic/beats/blob/master/filebeat/etc/filebeat.template.json](https://github.com/elastic/beats/blob/master/filebeat/etc/filebeat.template.json)

Let me know in case it doesn't work with the "routing" inside LS filters.

---

<div class="post-metadata">

### Author: ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)
#### Post date: [December 10, 2015, 5:43pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/8 "2015-12-10T17:43:57Z")

</div>

Thanks @ruflin , this template syntax for geo look correct? for filebeat to properly index geo values?

```
{
  "mappings": {
    "_default_": {
      "_all": {
        "enabled": true,
        "norms": {
      "enabled": false
    }
  },
  "dynamic_templates": [
    {
      "template1": {
        "mapping": {
          "doc_values": true,
          "ignore_above": 1024,
          "index": "not_analyzed",
          "type": "{dynamic_type}"
        },
        "match": "*"
      }
    }
  ],
  "properties": {
    "@timestamp": {
      "type": "date"
      },
      "message": {
      "type": "string",
      "index": "analyzed"
    },
    "offset": {
      "type": "long",
      "doc_values": "true"
    },
	"geoip" : {
        "dynamic" : "true",
        "properties" : {
          "ip" : {
            "type" : "ip"
          },
          "latitude" : {
            "type" : "float"
          },
          "location" : {
            "type" : "geo_point"
          },
          "longitude" : {
            "type" : "float"
          }
        }
      }
    }
   }
 },
   "settings": {
   "index.refresh_interval": "5s"
  },
  "template": "filebeat-*"
}
```

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 14, 2015, 8:03pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/9 "2015-12-14T20:03:52Z")

</div>

Looks ok, but perhaps @monica can have a quick look at it? Best is to try it out 🙂

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [December 14, 2015, 8:58pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/10 "2015-12-14T20:58:39Z")

</div>

There is an issue in loading the index patterns in Kibana (using the [load.sh](http://load.sh) script) that overwrites the index pattern in the default search, breaking the logstash-\* related dashboards and visualizations.

---

<div class="post-metadata">

### Author: ![abdalians](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@abdalians](https://discuss.elastic.co/u/abdalians)
#### Post date: [January 21, 2016, 9:28pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/11 "2016-01-21T21:28:44Z")

</div>

We seem to be getting this problem as well. The - in the hostname and/or the [beat.name](http://beat.name) makes the dashboard show multiple entries for a [beat.name](http://beat.name).

---

<div class="post-metadata">

### Author: ![plonka2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plonka2000/32/5077_2.png) [@plonka2000](https://discuss.elastic.co/u/plonka2000)
#### Post date: [February 12, 2016, 1:22pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/12 "2016-02-12T13:22:18Z")

</div>

> [@abdalians](#):
>
> The - in the hostname and/or the beat.name makes the dashboard show multiple entries for a beat.name.

I've noticed the same problem with the beats-dashboards-1.1.0 release.

It seems like a kibana issue, as in theory the ES data is complete, and the hyphen "-" is just another text character.

Has anyone seen a way to fix this in kibana?

Perhaps its a bug?

---

<div class="post-metadata">

### Author: ![Maarten\_Van\_Damme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maarten_van_damme/32/8159_2.png) [@Maarten\_Van\_Damme](https://discuss.elastic.co/u/Maarten_Van_Damme)
#### Post date: [February 29, 2016, 11:45am UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/13 "2016-02-29T11:45:37Z")

</div>

I am also having the same issue with beats-dashboards-1.1.1  
hostnames containing a hyphen are split as seperate machines on the dashboard.  
Any solution for this?

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 29, 2016, 12:55pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/14 "2016-02-29T12:55:19Z")

</div>

have you applied the index template to elasticsearch before starting topbeat?

---

<div class="post-metadata">

### Author: ![plonka2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plonka2000/32/5077_2.png) [@plonka2000](https://discuss.elastic.co/u/plonka2000)
#### Post date: [February 29, 2016, 1:06pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/15 "2016-02-29T13:06:22Z")

</div>

> [@Maarten\_Van\_Damme](#):
>
> Any solution for this?

Hey @Maarten_Van_Damme, check [this thread](https://discuss.elastic.co/t/new-index-pattern-to-current-index-topbeat/41627/10) out, I think it should help you.

---

<div class="post-metadata">

### Author: ![Maarten\_Van\_Damme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maarten_van_damme/32/8159_2.png) [@Maarten\_Van\_Damme](https://discuss.elastic.co/u/Maarten_Van_Damme)
#### Post date: [February 29, 2016, 2:17pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/16 "2016-02-29T14:17:23Z")

</div>

Yes, I have.

---

<div class="post-metadata">

### Author: ![plonka2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plonka2000/32/5077_2.png) [@plonka2000](https://discuss.elastic.co/u/plonka2000)
#### Post date: [February 29, 2016, 4:11pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/17 "2016-02-29T16:11:46Z")

</div>

Did you manage to fix it @Maarten_Van_Damme ?

I'd advise following all the steps I put out in the thread I linked.

Note that you will need to delete **_ALL_** `filebeat-*` indices in that method.

---

<div class="post-metadata">

### Author: ![Maarten\_Van\_Damme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maarten_van_damme/32/8159_2.png) [@Maarten\_Van\_Damme](https://discuss.elastic.co/u/Maarten_Van_Damme)
#### Post date: [March 1, 2016, 5:28am UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/18 "2016-03-01T05:28:50Z")

</div>

Hi Kareem,  
Will test your link today and post the results. thx

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [March 1, 2016, 2:11pm UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/19 "2016-03-01T14:11:55Z")

</div>

You can also look directly at the mapping used by Elasticsearch for an index. With this you can then check to see if hostname is correctly set as `not_analyzed`.

```auto
$ curl http://localhost:9200/topbeat-2016.03.01/_mapping?pretty
    "mappings": {
...
          "beat": {
            "properties": {
              "hostname": {
                "type": "string",
                "index": "not_analyzed",
                "ignore_above": 1024
              },
...

```

---

<div class="post-metadata">

### Author: ![Maarten\_Van\_Damme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maarten_van_damme/32/8159_2.png) [@Maarten\_Van\_Damme](https://discuss.elastic.co/u/Maarten_Van_Damme)
#### Post date: [March 2, 2016, 8:04am UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790/20 "2016-03-02T08:04:40Z")

</div>

I have it working now.  
I stopped all clients from sending data to elasticsearch, erased all elasticsearch data, restarted my clients (topbeat and filebeat services) and then the server names showed up correctly.  
Thanks for the help guys, much appreciated.

[Next page](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790.md?page=2)
