# Fleet managed Elastic Agent environment/deployment name? custom field?

**URL:** https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565
**Category:** Beats
**Tags:** fleet, elastic-agent
**Created:** [August 26, 2021, 11:07am UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565 "2021-08-26T11:07:53Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![mohsen0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsen0/32/58356_2.png) [@mohsen0](https://discuss.elastic.co/u/mohsen0)
#### Post date: [August 26, 2021, 11:07am UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/1 "2021-08-26T11:07:53Z")

</div>

Hi

I was wondering if there is a way to pass parameters to elastic agents when enrolling happens, to differentiate logs pushed from different environments.

On the other hand they are some configuration that can be set with hostnamectl that is for this purpose, I wonder that could be a feature for filebeat and elastic agent to push next to other host.\* details.  
[https://www.freedesktop.org/software/systemd/man/hostnamectl.html#deployment%20[ENVIRONMENT]](https://www.freedesktop.org/software/systemd/man/hostnamectl.html#deployment%20%5BENVIRONMENT%5D)  
Thanks  
Mohsen

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [August 26, 2021, 1:23pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/2 "2021-08-26T13:23:03Z")

</div>

There is no such option at the moment. Can you share some examples on what values you would like to set?

---

<div class="post-metadata">

### Author: ![mohsen0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsen0/32/58356_2.png) [@mohsen0](https://discuss.elastic.co/u/mohsen0)
#### Post date: [August 26, 2021, 1:35pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/3 "2021-08-26T13:35:13Z")

</div>

the values could be " `development` ", " `integration` ", " `staging` ", " `production` ".

---

<div class="post-metadata">

### Author: ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)
#### Post date: [August 26, 2021, 8:43pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/4 "2021-08-26T20:43:31Z")

</div>

You can kind of do this with the existing tools by:  
Using a policy for each environment, and set the namespace for that policy to the environment name. This would separate the data at the index level, but you can also filter via the `data_stream.namespace` field value as well. (This doesn't exactly work for somethings, I believe the osquery management module needs to use the `default` namespace, but I think this is the only integration with this limitation).

This is technically the purpose of the `namespace` value according to [ECS](https://www.elastic.co/guide/en/ecs/current/ecs-data_stream.html#field-data-stream-namespace)

---

<div class="post-metadata">

### Author: ![mohsen0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsen0/32/58356_2.png) [@mohsen0](https://discuss.elastic.co/u/mohsen0)
#### Post date: [August 27, 2021, 8:09am UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/5 "2021-08-27T08:09:06Z")

</div>

That does not scale very well, when there are more than 10 environments, keeping the configurations consistent across policies is a pain.  
The use case here is only to differentiate streams pushed from different environments.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [August 30, 2021, 7:57am UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/6 "2021-08-30T07:57:54Z")

</div>

We likely need to separate two different "use cases" here. If we talk about "staging", "production" the idea is indeed to use data streams. This also allows to easily give different access permissions per namespace.

And then there is "tags/labels" and additional host details which might be different per host. These likely should be set on the Elastic Agent and not in the policy itself. Adding metadata per agent is something we discussed in the past but did not implement yet.

@mohsen0 One thing I'm wondering is that you mention above the common "stating", "production" etc but then also about 10+ environments. Can you elaborate a bit more on what these will be?

---

<div class="post-metadata">

### Author: ![mohsen0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsen0/32/58356_2.png) [@mohsen0](https://discuss.elastic.co/u/mohsen0)
#### Post date: [August 30, 2021, 11:11pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/7 "2021-08-30T23:11:39Z")

</div>

As you know it is common to have some pre-live environments and then production environments. but some sectors demand dedicated hosting of our platform to separate their data from others. then 'you end up with 10+ production environments'.  
I believe the elastic stack solution [elastic.co](http://elastic.co) provides is a good example. each customer will get their own dedicated deployment. labelling log events from different workloads are very important to query them independently.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [September 1, 2021, 7:21am UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/8 "2021-09-01T07:21:26Z")

</div>

Basically you are collecting logs for multiple "customers" and each should have its own namespace. That make sense.

But for all "namespaces" you have a very similar / identical config and you would like to reuse it as the only thing that is different is the namespace, correct? As you have found out yourself, it is not something that we support today but I think is an interesting use case. I see multiple ways on how this could be solved. I think this would be worth to open a Github issue with the use case as a feature request. Best in the Kibana repo ([GitHub - elastic/kibana: Your window into the Elastic Stack](https://github.com/elastic/kibana)) as I think it is something we would need to solve in Fleet.

@Nima_Rezainia FYI

---

<div class="post-metadata">

### Author: ![Nima\_Rezainia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nima_rezainia/32/88626_2.png) [@Nima\_Rezainia](https://discuss.elastic.co/u/Nima_Rezainia)
#### Post date: [September 1, 2021, 6:01pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/9 "2021-09-01T18:01:55Z")

</div>

@mohsen0 the best way to segregate the data from each environment is to create a policy specific to that environment and set the namespace (as it was mentioned above). You'll get a unique Enrollment Token that make agent membership into the policy seamless.  
Would a policy "clone" action help in this case to ease the pain of re-applying the configurations?

The other unrelated thought is the tagging option during installation. an option to the Elastic Agent command allowing the user to pass in "Tags/Labels" and having these labels show up on the fleet console.

---

<div class="post-metadata">

### Author: ![mohsen0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsen0/32/58356_2.png) [@mohsen0](https://discuss.elastic.co/u/mohsen0)
#### Post date: [September 2, 2021, 1:41pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/10 "2021-09-02T13:41:36Z")

</div>

@Nima_Rezainia Setting up individual policies is too much manual work. we store the configuration in code in order to spin up environments very quickly and without any mistakes. Supporting setting you have mentioned (Tags/labels or even the org id) in enrollment of agent into fleet manager would be ideal.  
Otherwise, we have to go toward the direction of adding the field in the logs of the application which is not ideal for us since it requires development work for each service (or use filebeat since we can add fields there).

@ruflin :

> But for all "namespaces" you have a very similar / identical config and you would like to reuse it as the only thing that is different is the namespace, correct?

Yes that is correct

---

<div class="post-metadata">

### Author: ![mohsen0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsen0/32/58356_2.png) [@mohsen0](https://discuss.elastic.co/u/mohsen0)
#### Post date: [September 2, 2021, 1:51pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/11 "2021-09-02T13:51:41Z")

</div>

> <https://github.com/elastic/kibana/issues/110988>
>
> Ability to set labels or tags during installation or enrolment agent 
> so that d…ifferent identical deployments of service can be differentiated in the dataset
> 
> The specific use case is described in: https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/6
> 
> \`\`\`
> sudo ./elastic-agent install -f --url=https://\<feet manager\>:443 --enrollment-token=\<token\> --tag=staging01 
> \`\`\`
> or in case, the agent is already installed via package manager
> \`\`\`
> elastic-agent enroll -f --url=https://\<feet manager\>:443 --enrollment-token=\<token\> --tag=staging01 
> \`\`\`

---

<div class="post-metadata">

### Author: ![Nima\_Rezainia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nima_rezainia/32/88626_2.png) [@Nima\_Rezainia](https://discuss.elastic.co/u/Nima_Rezainia)
#### Post date: [September 2, 2021, 3:59pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/12 "2021-09-02T15:59:26Z")

</div>

thank you for raising this issue.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 30, 2021, 5:59pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-environment-deployment-name-custom-field/282565/13 "2021-09-30T17:59:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
