# Environment Variable as Custom Field - Fleet Policy

**URL:** <https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568>\
**Category:** Elastic Agent\
**Created:** [June 27, 2025, 2:48pm UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568 "2025-06-27T14:48:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [June 27, 2025, 2:48pm UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/1 "2025-06-27T14:48:42Z")

</div>

Hi,  
We are trying to fetch an environment variable to be added as a field for every log message coming in from the server where elastic agent is deployed. Similar to this [issue link](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/2)  
The Elastic agent deployments are fleet enrolled  
**Setup Details**

- **Cluster 1 - Version details:**  
-- Elastic Agent: 8.16.6 and 8.12.2  
-- ES and Kibana : 8.18.1  
-- Fleet Server : 8.18.1  
-- Elastic Defend Integration: v8.18.1-prerelease.0

- **Cluster 2 - Version details:**  
-- Elastic Agent: 8.16.6 and 8.12.2  
-- ES and Kibana : 8.17.0  
-- Fleet Server : 8.17.0  
-- Elastic Defend Integration: v8.17.1

- Tried custom field options - no luck with no error messages and the datastream totally stops from that agent.  
-- ${env.VARIABLE\_NAME}  
-- {env.VARIABLE\_NAME}  
-- ${VARIABLE\_NAME}

- Tried adding the `process.env.vars` , which did bring some events with value `VARIABLE_NAME=variable_value`

- Tried the enrichment value as well, no new field added but the datastream runs fine.

**Objective** :

- Have this field (application ID) available in every log message which can then be queried by application owners from a common ECE instance with required access permissions.
- Tagging alerts and enrichment with data against other tools which also have same VARIABLE\_NAME and value

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [July 1, 2025, 8:05am UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/2 "2025-07-01T08:05:56Z")

</div>

Alright so there are few things I had configure to achieve this (not completely clean)

1. Update the elastic-agent service to pick a environment variable, in my case `DEPLOYMENT_NAME=edragent1` Ideally have an override.conf.
2. Since this policy has only a defend integration, update the following in the advanced setting as `Custom.app_id=${env.DEPLOYMENT_NAME}` within `linux.advanced.document_enrichment.fields `
3. You should be able to get that field however it will not be Mapped and that is to be handled on the template side.
4. Conclusion - Custom field option on the policy setting will not work with Elastic Defend integration unless someone comes with a WOW solution!! please help 🙂

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 1, 2025, 12:35pm UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/3 "2025-07-01T12:35:57Z")

</div>

As mentioned in your Slack thread on the public slack, this is indeed how it works.

It seems that custom fields does not work for some type of inputs according to the [documentation](https://www.elastic.co/guide/en/fleet/8.18/agent-policy.html#add-custom-fields).

> Note that adding custom tags is not supported for a small set of inputs:
> 
> - `apm`
> - `cloudbeat` and all `cloudbeat/*` inputs
> - `cloud-defend`
> - `fleet-server`
> - `pf-elastic-collector`, `pf-elastic-symbolizer`, and `pf-host-agent`
> - `endpoint` inputs. Instead, use the advanced settings (`*.advanced.document_enrichment.fields`) of the Elastic Defend Integration.

Your approach is the correct one.

I think that this information should be more clear and present on the agent settings configuration as well.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [July 2, 2025, 12:47pm UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/4 "2025-07-02T12:47:34Z")

</div>

Hi @karnamonkster, unfortunately no, Endpoint doesn't expect environment variables to resolve in the custom values.

PS. Even if it did that the variable would have to be set on `ElasticEndpoint` service, not `elastic-agent`

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [July 3, 2025, 8:04am UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/5 "2025-07-03T08:04:18Z")

</div>

I think that might be the case, do we know if there is a possibility to have it?  
Also we can add a warning while adding custom fields on Policy level for integration type similar to what happens when you select `fleet-server` integration.  
We are now going ahead with the pipeline processor to map and rename the unmapped field

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [July 4, 2025, 11:05am UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/6 "2025-07-04T11:05:51Z")

</div>

This Endpoint feature wasn't meant to handle custom processors like the fleet.

I'd suggest to file enhancement request issue about this on [GitHub - elastic/endpoint](https://github.com/elastic/endpoint)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 4, 2025, 1:14pm UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/7 "2025-07-04T13:14:47Z")

</div>

I think that one of the issues is that this is not clear on the configuration page for the policy settings, it should have an warning saying that custom fields do not work for the Endpoint integration in the same way that we get an warning saying that the Logstash output does not work for Fleet Server.

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [July 4, 2025, 1:17pm UTC](https://discuss.elastic.co/t/environment-variable-as-custom-field-fleet-policy/379568/8 "2025-07-04T13:17:56Z")

</div>

- Sure, i will put in the request, but if there is an option to provide enrichment data / fields, they should be mapped at least, and should have `ignore_missing` by default. Cause for some reason a server does not run the service with that environment variable shouldn't stop sending all datastreams.

- We will ensure first to have all the elastic agents restarted to capture that environment variable running EDR, then we move ahead with the enrichment fields

- We have a working solution now after setting that in the index template and a custom pipeline with an ingest processor.
