# Hostname not extracted when i run logstash as a service on rhel

**URL:** <https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977>\
**Category:** Logstash\
**Created:** [November 25, 2023, 6:37pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977 "2023-11-25T18:37:32Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [November 25, 2023, 6:37pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/1 "2023-11-25T18:37:32Z")

</div>

Hi  
When i run logstash normally like this:  
./logstash -f logstash.cfg

It extract hostname.

But when i run as service not extract hostname.

Any idea?  
Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 25, 2023, 7:04pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/2 "2023-11-25T19:04:58Z")

</div>

What OS?

share your `logstash.cfg`

Share sample document with and without

---

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [November 25, 2023, 7:53pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/3 "2023-11-25T19:53:38Z")

</div>

@stephenb, os is rhel8

```auto
input {
  file {
    path => "/home/app/logs/2023.log"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    exclude => ["*.gz" , "*.bz2" , "*.slice"]
    codec => plain { charset => "UTF-8" }
  }
}

filter {

    mutate
    {
        replace => { "host" => "${HOSTNAME}"}

        replace => { "IP_INFLUX" => "192.168.1.1"}
        replace => { "BUCKET_INFLUX" => "mybucket"}
        replace => { "TOKEN_INFLUX" => "mytoken"}
        replace => { "ORG_INFLUX" => "myorg"}
    }

    mutate
    {
        replace => { "URL" => "http://%{[IP_INFLUX]}:8087/api/v2/write?bucket=%{[BUCKET_INFLUX]}&precision=s&org=%{[ORG_INFLUX]}"}
    }

output
{
    if "GW_In" in [tags]

    {
  http {
    url => "%{[URL]}"
    http_method => "post"
    format => message
    message => 'APP_In,Thread=%{[Thread]},host=%{[host]},R=%{[R]},I=%{[I]} uid="%{[uid]}"'

    headers => [
      'Authorization', 'Token %{[TOKEN_INFLUX]}'
    ]
  }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 25, 2023, 8:17pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/4 "2023-11-25T20:17:26Z")

</div>

And what do the output documents look like for each?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 25, 2023, 8:29pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/5 "2023-11-25T20:29:42Z")

</div>

> [@Indeed2000](#):
>
> `replace => { "host" => "${HOSTNAME}"}`

Oh you're doing that! Well that's because when you start as the system service that environment variable is not set.

You should be getting the `host.name` as part of the event

What version?

Perhaps look at

> [@Why doesn't add\_tag =\> \["${HOSTNAME}"\] work?](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/19):
>
> @magnusbaeck, With the help of elastic support, we figured this out. Turns out it was 2 easy changes to get it working. I am not saying that it was easy figuring this out, because it wasn't easy! mutate { add\_tag =\> ["${HOSTNAME}"] } Add xpack.management.pipeline.id: to logstash.yml Create file, /etc/sysconfig/logstash, (chmod 600) and add these 2 lines HOSTNAME=ThisHostName LOGSTASH\_KEYSTORE\_PASS=password Thanks again for your help!

---

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [November 26, 2023, 2:03am UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/6 "2023-11-26T02:03:28Z")

</div>

@stephenb logstash 8.11

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 26, 2023, 2:30am UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/7 "2023-11-26T02:30:37Z")

</div>

Did you see my previous post... Probably explains your issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2023, 2:31am UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/8 "2023-12-24T02:31:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
