# Hostname.raw appears twice in split chart

**URL:** <https://discuss.elastic.co/t/hostname-raw-appears-twice-in-split-chart/40481>\
**Category:** Kibana\
**Created:** [January 29, 2016, 1:45pm UTC](https://discuss.elastic.co/t/hostname-raw-appears-twice-in-split-chart/40481 "2016-01-29T13:45:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nielsk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nielsk/32/7460_2.png) [@nielsk](https://discuss.elastic.co/u/nielsk)\
**Post date:** [January 29, 2016, 1:45pm UTC](https://discuss.elastic.co/t/hostname-raw-appears-twice-in-split-chart/40481/1 "2016-01-29T13:45:39Z")

</div>

I am creating a couple of bar-charts from Logstash-data and I do a split chart to differentiate a couple of servers. I do that by using a sub aggregation "Terms" and use the field hostname.raw.  
Now I see for several servers that they appear twice in the chart as the following:

- servername
- servername.domain.tld

Is there a way to combine them when splitting them automatically by Hostname.raw? I could use host.raw but that gives me an IP-addressand I'd really prefer DNS-names.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 29, 2016, 4:18pm UTC](https://discuss.elastic.co/t/hostname-raw-appears-twice-in-split-chart/40481/2 "2016-01-29T16:18:47Z")

</div>

You could potentially use a [script](https://www.elastic.co/guide/en/elasticsearch/reference/2.x/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script) or if you have a small number of hostnames, you could use the [filters aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current//search-aggregations-bucket-filters-aggregation.html) to create a bucket for each host.

But really the best thing to do here would be to fix the problem in the data. Why are you getting different values in hostname.raw for the same host in the first place? Can you modify your log data or use logstash to normalize this data before it gets to Elasticsearch? Having good data always makes things much easier down the road.

---

<div class="post-metadata">

**Author:** ![nielsk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nielsk/32/7460_2.png) [@nielsk](https://discuss.elastic.co/u/nielsk)\
**Post date:** [January 29, 2016, 4:37pm UTC](https://discuss.elastic.co/t/hostname-raw-appears-twice-in-split-chart/40481/3 "2016-01-29T16:37:02Z")

</div>

Thanks, I will have a look at those links on Monday.  
I thought about why I get those different host names as well but I have no clue. I use only one filter for Windows logs and the logs come from nxlog. It is weird…  
I will look into that more on Monday, too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:03pm UTC](https://discuss.elastic.co/t/hostname-raw-appears-twice-in-split-chart/40481/4 "2017-07-06T14:03:54Z")

</div>


