# Host showing as %{host2} in kibana web

**URL:** <https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092>\
**Category:** Logstash\
**Created:** [May 3, 2016, 5:58pm UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092 "2016-05-03T17:58:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bsmitty111](https://avatars.discourse-cdn.com/v4/letter/b/4da419/32.png) [@bsmitty111](https://discuss.elastic.co/u/bsmitty111)\
**Post date:** [May 3, 2016, 5:58pm UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/1 "2016-05-03T17:58:04Z")

</div>

hello, when I open Kibana, the host mapping field in a search is showing as %{host2} and not the host name, I am not sure what config to look in to resolve this.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 3, 2016, 8:18pm UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/2 "2016-05-03T20:18:44Z")

</div>

It looks like your Logstash configuration tries to reference a field named `host2` but no such field existed for the event. Look into your Logstash configuration.

---

<div class="post-metadata">

**Author:** ![bsmitty111](https://avatars.discourse-cdn.com/v4/letter/b/4da419/32.png) [@bsmitty111](https://discuss.elastic.co/u/bsmitty111)\
**Post date:** [May 4, 2016, 10:57am UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/3 "2016-05-04T10:57:24Z")

</div>

Thank you, in my logstash indexer config file, i have this under filter {  
mutate {  
replace =\> ["host", "%{host2}"]

I am guessing this is where the %{host2} is coming from, but I am not sure how to fix this.  
It looks like other configs I have found on line.

> **[Logstash / Elasticsearch / Kibana for Windows Event Logs](http://www.ragingcomputer.com/2014/02/logstash-elasticsearch-kibana-for-windows-event-logs)**
>
> Edit: This post is pretty old and Elasticsearch/Logstash/Kibana have evolved a lot since it was written. Part 1 of 4 - Part 2 - Part 3 - Part 4 Have you heard of Logstash / ElasticSearch / Kibana? I don't wanna oversell it, but it's AMAZING! I'll...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2016, 6:17am UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/4 "2016-05-09T06:17:19Z")

</div>

> I am guessing this is where the %{host2} is coming from, but I am not sure how to fix this.

You're relying on a `host2` field to exist, but there is no such field. When and how is this field supposed to be created? It would help if you shows us your filter configuration and example messages.

I also suggest that you edit this post to move it to the Logstash category since it isn't a Kibana problem.

---

<div class="post-metadata">

**Author:** ![bsmitty111](https://avatars.discourse-cdn.com/v4/letter/b/4da419/32.png) [@bsmitty111](https://discuss.elastic.co/u/bsmitty111)\
**Post date:** [May 9, 2016, 12:33pm UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/5 "2016-05-09T12:33:08Z")

</div>

Thank you for the reply,

As I mentioned, I have inherited this, and am not very proficient in logstash/elasticsearch or kibana.

Here is what the filter section on my index server has.

filter {  
grok {  
match =\> ["host", "^(?[0-2]?[0-9]?[0-9].[0-2]?[0-9]?[0-9].[0-2]?[0-9]?[0-9].[0-2]?[0-9]?[0-9]):.\*" ]  
}  
mutate {  
replace =\> ["host", "%{host2}"]  
}  
mutate {  
remove\_field =\> ["host2"]  
}

```
if [type] == "WindowsEventLog" {
    mutate {
        lowercase => ["EventType", "FileName", "Hostname", "Severity"]
    }
    mutate {
        rename => ["Hostname", "source_host"]
    }
    mutate {
        gsub => ["source_host","\.example\.com",""]
    }
    date {
        match => ["EventTime", "YYYY-MM-dd HH:mm:ss"]
    }
    mutate {
        rename => ["Severity", "eventlog_severity"]
        rename => ["SeverityValue", "eventlog_severity_code"]
        rename => ["Channel", "eventlog_channel"]
        rename => ["SourceName", "eventlog_program"]
        rename => ["SourceModuleName", "nxlog_input"]
        rename => ["Category", "eventlog_category"]
        rename => ["EventID", "eventlog_id"]
        rename => ["RecordNumber", "eventlog_record_number"]
        rename => ["ProcessID", "eventlog_pid"]
    }

    if [SubjectUserName] =~ "." {
        mutate {
            replace => ["AccountName", "%{SubjectUserName}"]
        }
    }
    if [TargetUserName] =~ "." {
        mutate {
            replace => ["AccountName", "%{TargetUserName}"]
        }
    }
    if [FileName] =~ "." {
        mutate {
            replace => ["eventlog_channel", "%{FileName}"]
        }
    }

    mutate {
        lowercase => ["AccountName", "eventlog_channel"]
    }

    mutate {
        remove_field => ["SourceModuleType", "EventTimeWritten", "EventReceivedTime", "EventType"]
    }
}

```

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2016, 12:36pm UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/6 "2016-05-09T12:36:17Z")

</div>

Well, there's nothing in the configuration you've shown that creates a `host2` field. I don't know what you're trying to do.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2016, 12:39pm UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/7 "2016-05-09T12:39:33Z")

</div>

Ah, wait. Look at this line:

> match =\> ["host", "^(?[0-2]?[0-9]?[0-9].[0-2]?[0-9]?[0-9].[0-2]?[0-9]?[0-9].[0-2]?[0-9]?[0-9]):.\*" ]

I'm pretty sure you actually have `<host2>` or similar after the first question mark. Always format configuration file snippets as code to make sure they come through correctly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/host-showing-as-host2-in-kibana-web/49092/8 "2017-07-06T04:58:32Z")

</div>


