# Hostname not extracted when i run logstash as a service on rhel

**URL:** <https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977>\
**Category:** Logstash\
**Created:** [November 25, 2023, 6:37pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977 "2023-11-25T18:37:32Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 25, 2023, 8:29pm UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977/5 "2023-11-25T20:29:42Z")

</div>

> [@Indeed2000](#):
>
> `replace => { "host" => "${HOSTNAME}"}`

Oh you're doing that! Well that's because when you start as the system service that environment variable is not set.

You should be getting the `host.name` as part of the event

What version?

Perhaps look at

> [@Why doesn't add\_tag =\> \["${HOSTNAME}"\] work?](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/19):
>
> @magnusbaeck, With the help of elastic support, we figured this out. Turns out it was 2 easy changes to get it working. I am not saying that it was easy figuring this out, because it wasn't easy! mutate { add\_tag =\> ["${HOSTNAME}"] } Add xpack.management.pipeline.id: to logstash.yml Create file, /etc/sysconfig/logstash, (chmod 600) and add these 2 lines HOSTNAME=ThisHostName LOGSTASH\_KEYSTORE\_PASS=password Thanks again for your help!

---

_[View the full topic](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977)._
