# Filter to send only system shortnames

**URL:** <https://discuss.elastic.co/t/filter-to-send-only-system-shortnames/295704>\
**Category:** Logstash\
**Created:** [January 28, 2022, 12:49pm UTC](https://discuss.elastic.co/t/filter-to-send-only-system-shortnames/295704 "2022-01-28T12:49:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![StuWhitby](https://avatars.discourse-cdn.com/v4/letter/s/8797f3/32.png) [@StuWhitby](https://discuss.elastic.co/u/StuWhitby)\
**Post date:** [January 28, 2022, 12:49pm UTC](https://discuss.elastic.co/t/filter-to-send-only-system-shortnames/295704/1 "2022-01-28T12:49:32Z")

</div>

Hi,

I'm new to Logstash, and attempting to update our company's configuration which currently sends syslog data to Splunk.

I've searched on how to standardise the system naming, which may have the shortname or the longname or the IP.

I've successfully "replace"d the name using

```auto
filter {
  if [host] == "10.10.200.33" {
  mutate {
    replace => ["host", "firewall"]
    }
  }
}

```

That works. However.....

```auto
filter {
  split => ["host", "."]
  }
  mutate {
    replace => ["host", "%{[host][0]}"]
  }
}

```

gives a result in Splunk that simply shows:

hostname: %{[hostname][0]}

The `split => ["host", "."]` section is really a straight copy from other posts on this forum where there's been a "thanks, that works" response. I can't figure out why my filter's giving the string rather than giving the variable.

Any help appreciated.

Thanks,

Stuart.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 28, 2022, 1:17pm UTC](https://discuss.elastic.co/t/filter-to-send-only-system-shortnames/295704/2 "2022-01-28T13:17:27Z")

</div>

Can you give an example of your data?

Also, I think you want to use the `split` action from the `mutate` filter, not the `split` filter, they are different things.

The `split` filter will split an array into multiple events, the `split` action from the `mutate` filter will split a string into an array based on a delimiter, but it won't create new events.

If you have something like this:  
`hostname`: `host.local.domain` and you want to have `hostname`: [`host`, `local`, `domain`], then you need the `split` action from the `mutate` filter.

```auto
mutate {
    split => { "hostname" => "."}
}

```

This way you can access the data using `%{[hostname][index]}`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2022, 1:18pm UTC](https://discuss.elastic.co/t/filter-to-send-only-system-shortnames/295704/3 "2022-02-25T13:18:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
