# Environment name instead of hostname

**URL:** <https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [May 22, 2022, 8:06pm UTC](https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359 "2022-05-22T20:06:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anagha\_nambiar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anagha_nambiar/32/97593_2.png) [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Post date:** [May 22, 2022, 8:06pm UTC](https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359/1 "2022-05-22T20:06:47Z")

</div>

Hi All,

Suppose I have installed metricbeat in 3 servers and their machine names are IIS1, IIS2 and IIS3.  
If I have to filter metric data for dashboard creation in Kibana, then I used the query "agent.hostname"or "host.name".

It is quite difficult to differentiate servers using hostname. We would rather use environment names like below:

IIS1 - Dev  
IIS2 - SIT  
IIS3 - PROD

Could you suggest a way or provide some steps on using environment names instead of hostnames for metricbeat in Kibana dashboard?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 22, 2022, 9:32pm UTC](https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359/2 "2022-05-22T21:32:03Z")

</div>

FB and MB give you an option to define tags or additional fields:

```auto
# The tags of the shipper are included in their own field with each
# transaction published.
tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the
# output.
fields:
  env: staging

```

This will not have backward values, unless you do reindexing.  
If you have a lot of servers, I would use fields.env: dev/SIT/PROD and tags for application, location or something more specific, e.g. app-name, exchange, London, Paris... Tags can have multiple values.

---

<div class="post-metadata">

**Author:** ![Anagha\_nambiar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anagha_nambiar/32/97593_2.png) [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Post date:** [May 23, 2022, 5:51am UTC](https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359/3 "2022-05-23T05:51:51Z")

</div>

Okay, how can I filter this value from Kibana dashboard?  
I have added the environment "Dev" which is having tag as "test" and hostname is "IIS1".

If I give "agent.hostname" query, will I get the "Dev" listed instead of hostname?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 23, 2022, 7:19am UTC](https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359/4 "2022-05-23T07:19:42Z")

</div>

No, you will not have the value replacement. Instead you will additional field/tag which will help in the filtering. You will have to modify the dashboard based on named fields.  
Use fields.env or fields.hostalias to add a hostname alias.

If you want to replace the value use script processor [link](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/253574)

> **[Script Processor | Metricbeat Reference \[8.2\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/processor-script.html)**

---

<div class="post-metadata">

**Author:** ![Anagha\_nambiar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anagha_nambiar/32/97593_2.png) [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Post date:** [May 23, 2022, 4:29pm UTC](https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359/5 "2022-05-23T16:29:15Z")

</div>

Thank you @Rios . That worked!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2022, 6:29pm UTC](https://discuss.elastic.co/t/environment-name-instead-of-hostname/305359/6 "2022-06-20T18:29:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
