# Hosts duplicated with and without fqdn

**URL:** <https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546>\
**Category:** SIEM\
**Created:** [June 24, 2020, 6:36pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546 "2020-06-24T18:36:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christian\_SANCHEZ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_sanchez/32/43557_2.png) [@Christian\_SANCHEZ](https://discuss.elastic.co/u/Christian_SANCHEZ)\
**Post date:** [June 24, 2020, 6:36pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/1 "2020-06-24T18:36:45Z")

</div>

Hi

I have 7.8 beats installed on Windows servers (audit, metric, file and winlog).

They all push events directly to ES

In the SIEM, i see my hosts duplicated : once with simple name, once with fqdn

It seems winlogbeat uses fqdn but not the others.

Is there a way (with sample) to align all my beats to use either simple name or fqdn ?

Thanks

---

<div class="post-metadata">

**Author:** ![madduck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madduck/32/63444_2.png) [@madduck](https://discuss.elastic.co/u/madduck)\
**Post date:** [June 26, 2020, 1:28pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/2 "2020-06-26T13:28:20Z")

</div>

Hello Christian,

if I am not mistaken the field "host.hostname" contains the shortname for winlogbeat.

---

<div class="post-metadata">

**Author:** ![Christian\_SANCHEZ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_sanchez/32/43557_2.png) [@Christian\_SANCHEZ](https://discuss.elastic.co/u/Christian_SANCHEZ)\
**Post date:** [June 26, 2020, 2:41pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/3 "2020-06-26T14:41:07Z")

</div>

Hello

You are right host.hostname is short on every beats.

But Winlogbeat is the only one with fqdn in the field host.name, and it seems it is host.name which is used for the SIEM Hosts table.

Is it something i can solve by configuring Kibana ? Elastic ? or is it something i need to change in my beat .yml file ?

I just need to have something unified and not duplicating displayed entries.

Thanks & Regards

---

<div class="post-metadata">

**Author:** ![madduck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madduck/32/63444_2.png) [@madduck](https://discuss.elastic.co/u/madduck)\
**Post date:** [June 29, 2020, 4:47pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/4 "2020-06-29T16:47:23Z")

</div>

Hello Christian,

there is a way to do this, however it would probably force you to re-index your windows index in order to have the same consistent name across your whole data. Otherwise you'll still see your Host two times.

I will give you a small write-up on how I achieved the shortname instead of the FQDN for my windows host:

What you need:

- Winlogbeat
- Logstash
- Elasticsearch

**winlogbeat.yml**  
Configure your Winlogbeat to send to a logstash instance.

Add a tag to identify this specific hosts logs.

```
processors:
  - add_tags:
       tags: "WindowsHost"

```

**Logstash**  
You need a logstash instance to make use of the mutate filter, more specifically its [Update Module](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-update).

Define a pipeline that looks for beat inputs. Mine looks like this:

**pipe-beats.conf**

```
input {
      beats {
        port => "5044"
      }
    }

filter {
  if "WindowsHost" in [tags]{
  mutate {
    update => { "[host][name]" => "YOUR_SHORTNAME" }
 }
  mutate {
    remove_tag => ["WindowsHost"]
 }
}
}

output {
  elasticsearch {
    hosts => ["${ES_1_PROT}://${ES_1_IP}:${ES_1_PORT_REST}","${ES_2_PROT}://${ES_2_IP}:${ES_2_PORT_REST}"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}"

    user => redacted
    password => redacted
  }
}

```

Disclaimer: You will need to create a pipeline.yml file in order to tell logstash where your pipeline is located.

The input part is rather self explanatory. It's looking for any beat input coming in through port 5044 (default logstash port)  
In the filter section we first check if the log has the Tag "WindowsHost", if that is the case we apply two different mutate filters.  
First we update the field host.name (it is imperative that you write it as [host][name], it will NOT work with host.name) with "YOUR\_SHORTNAME".  
Second, this is optional, we remove the WindowsHost tag

The output part just points the transformed log to your elasticsearch instance and the index I set up for it.  
Beware that I am using environment variables here.

I hope this helps

---

<div class="post-metadata">

**Author:** ![Christian\_SANCHEZ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_sanchez/32/43557_2.png) [@Christian\_SANCHEZ](https://discuss.elastic.co/u/Christian_SANCHEZ)\
**Post date:** [June 30, 2020, 9:02am UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/5 "2020-06-30T09:02:48Z")

</div>

Hi Madduck

Thanks for the answer and proposal.

Unfortunately, Logstash can not be involved in my landscape.

I saw that there is an open issue on that topic for winlogbeat on the GitHub ([https://github.com/elastic/beats/issues/18056](https://github.com/elastic/beats/issues/18056)).

In parallel, i tried to play with the processors of the Winlogbeat to copy the field from host.hostname into host.name, but it did not work.

I was wondering if it is possible to change the settings in SIEM to do not use host.name by host.hostname

My last chance would be to add an ingest processor in Elasticsearch for every incoming Winlogbeat event.

Any other guess ?

Again, thanks for your support

Best regards

---

<div class="post-metadata">

**Author:** ![Christian\_SANCHEZ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_sanchez/32/43557_2.png) [@Christian\_SANCHEZ](https://discuss.elastic.co/u/Christian_SANCHEZ)\
**Post date:** [June 30, 2020, 10:59am UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/6 "2020-06-30T10:59:28Z")

</div>

Hello again

I declared an ingest pipeline in by ES instance.  
Configured my winlogbeat.yml to use the pipeline  
Works like a charm.

Ticket can be closed for now, even if it should be fixed within the github issue.

Thanks again

---

<div class="post-metadata">

**Author:** ![madduck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madduck/32/63444_2.png) [@madduck](https://discuss.elastic.co/u/madduck)\
**Post date:** [June 30, 2020, 12:28pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/7 "2020-06-30T12:28:47Z")

</div>

Hi Christian,

glad you found something that works for you.  
To tie into your earlier question about doing it with winlogbeat processors thats also possible.

```
processors:
  - drop_fields:
      fields: ["host.name"]
  - copy_fields:
      fields:
        - from: host.hostname
          to: host.name

```

You will have to drop the field first because the copy\_fields function cant write into already existing fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2020, 12:29pm UTC](https://discuss.elastic.co/t/hosts-duplicated-with-and-without-fqdn/238546/8 "2020-07-28T12:29:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
