# Filebeat central log server and hostname

**URL:** <https://discuss.elastic.co/t/filebeat-central-log-server-and-hostname/308832>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 4, 2022, 7:04pm UTC](https://discuss.elastic.co/t/filebeat-central-log-server-and-hostname/308832 "2022-07-04T19:04:19Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![parisila](https://avatars.discourse-cdn.com/v4/letter/p/3ec8ea/32.png) [@parisila](https://discuss.elastic.co/u/parisila)\
**Post date:** [July 12, 2022, 10:51pm UTC](https://discuss.elastic.co/t/filebeat-central-log-server-and-hostname/308832/2 "2022-07-12T22:51:52Z")

</div>

I resolved this and posted about it here:  
[Auditd ingest pipeline with forwarded logs - Elastic Stack / Beats - Discuss the Elastic Stack](https://discuss.elastic.co/t/auditd-ingest-pipeline-with-forwarded-logs/309054)

For syslogs and authlogs will not need the Digest processor but basically a processor in the individual module runs first. There check to see the original log file path and if not the central log server then add the forwarded tag. Also copied the fields host.hostname to host.name so both are populated correctly

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-central-log-server-and-hostname/308832)._
