# Hosts tab in SIEM and WEF

**URL:** <https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162>\
**Category:** SIEM\
**Created:** [July 12, 2019, 8:07am UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162 "2019-07-12T08:07:58Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![smerzlyakov](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Post date:** [July 12, 2019, 8:07am UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/1 "2019-07-12T08:07:58Z")

</div>

There is Hosts tab in SIEM. I think nobody in Enterprise uses Winlogbeat on every Windows hosts. It is standard to use collector for logs and send Logs using Windows Event Forwarding on it. So, in field Host it will be name of collector. Or just collect logs from AD DC.  
But in SIEM tab "Hosts" i defenetly want to see hostname of Users Windows stations.  
So, how to fix it?I do not want to rename fields, because it breakes existing Scheme. Maybe in future you will change the logic of this page?  
What is the best solution to see real hosts on this SIEM tab?

---

<div class="post-metadata">

**Author:** ![westywill](https://avatars.discourse-cdn.com/v4/letter/w/7bcc69/32.png) [@westywill](https://discuss.elastic.co/u/westywill)\
**Post date:** [August 2, 2019, 3:37pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/2 "2019-08-02T15:37:05Z")

</div>

We are also using WEF and Winlogbeats and seeing only the WEF host in the Hosts page under SIEM. Would love to either find out how to get the individual hosts to show up, if it's a feature request, or a bug.

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [August 5, 2019, 1:18pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/3 "2019-08-05T13:18:21Z")

</div>

By default, Winlogbeat adds the current hostname as `host.name` which is then displayed by the All Hosts table. Unfortunately, that's not the right thing when reading forwarded events.

What you can do is overwrite `host.name` with `winlog.computer_name` (I think that contains the hostname of the machine the events came from, but I'm not sure).

I haven't tested the following, but think it should work (in `winlogbeat.yml`):

```auto
processors:
  - script:
      lang: javascript
      id: forwarded_hostname
      source: >
        function process(event) {
          event.Put("host.name", event.Get("winlog.computer_name"));
        }

```

We've discussed some ways of making this easier, but this is probably the best we can do for now.

---

<div class="post-metadata">

**Author:** ![smerzlyakov](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Post date:** [August 13, 2019, 11:09am UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/4 "2019-08-13T11:09:00Z")

</div>

Thank you. I will try to check it!

---

<div class="post-metadata">

**Author:** ![candre.dabney](https://avatars.discourse-cdn.com/v4/letter/c/e36b37/32.png) [@candre.dabney](https://discuss.elastic.co/u/candre.dabney)\
**Post date:** [August 14, 2019, 12:01pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/5 "2019-08-14T12:01:55Z")

</div>

What would the fix be for a Linux/CentOS environment. using Filebeat and/or Auditbeat

---

<div class="post-metadata">

**Author:** ![crickes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crickes/32/18009_2.png) [@crickes](https://discuss.elastic.co/u/crickes)\
**Post date:** [August 15, 2019, 11:13am UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/6 "2019-08-15T11:13:40Z")

</div>

Did this work when you tested it? I'm trying to do the same and doesn't seem to be do anything.

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [August 15, 2019, 12:17pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/7 "2019-08-15T12:17:32Z")

</div>

> [@candre.dabney](#):
>
> What would the fix be for a Linux/CentOS environment. using Filebeat and/or Auditbeat

@candre.dabney The question here is about WEF (Windows Event Forwarding). I assume you mean something else? Do you mind opening a separate topic?

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [August 15, 2019, 12:19pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/8 "2019-08-15T12:19:35Z")

</div>

> [@crickes](#):
>
> Did this work when you tested it? I'm trying to do the same and doesn't seem to be do anything.

@crickes The script is supposed to overwrite `host.name` with `winlog.computer_name`. Do you have these in your events? Do you see any warnings/errors when running Winlogbeat with the script? Can you maybe post an example document from your environment?

---

<div class="post-metadata">

**Author:** ![crickes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crickes/32/18009_2.png) [@crickes](https://discuss.elastic.co/u/crickes)\
**Post date:** [August 15, 2019, 1:36pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/9 "2019-08-15T13:36:30Z")

</div>

Hi. Yes both these fields are present but I'm not convinced we've got the processor defined correctly. As an alternative, I've used an ingest pipeline to remap these fields and that worked ok, but I'd rather figure out how to make the processor work in winlogbeat. I can't post an example document, but I can confirm that 'host.name' currently refers to our Windows Event Collector server where winlogbeat is running, and 'winlog.computer\_name' contains the name of the source of the event. With this script in place, i would expect them to bother report the latter value.

---

<div class="post-metadata">

**Author:** ![candre.dabney](https://avatars.discourse-cdn.com/v4/letter/c/e36b37/32.png) [@candre.dabney](https://discuss.elastic.co/u/candre.dabney)\
**Post date:** [August 15, 2019, 1:46pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/10 "2019-08-15T13:46:14Z")

</div>

sure I don't mind. Also just a heads up, I sent you a message explaining the issue as well.

---

<div class="post-metadata">

**Author:** ![crickes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crickes/32/18009_2.png) [@crickes](https://discuss.elastic.co/u/crickes)\
**Post date:** [August 15, 2019, 2:40pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/11 "2019-08-15T14:40:12Z")

</div>

This is the section of the yml file now with your suggested code. Is it in the right place?

```
#======================= Winlogbeat specific options ==========================
winlogbeat.event_logs:
  - name: Application
    ignore_older: 30m
  - name: Security
    ignore_older: 30m
  - name: System
    ignore_older: 30m
  - name: ForwardedEvents   
    processors:
      - script:
          when.equals.winlog.channel: Security
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js  
      - script:
          lang: javascript
          id: forwarded_hostname
          source: >
            function process(event) {
              event.Put("host.name" , event.Get("winlog.computer_name"));
            }
```

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [August 19, 2019, 12:24pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/12 "2019-08-19T12:24:15Z")

</div>

@crickes Yeah, that might have worked. I think what's happening is that the Beat is overwriting `host.name` _after_ the script executes. Can you try putting it into the top-level `processors` section (outside `winlogbeat.event_logs`) like this?

```auto
processors:
  - script:
    lang: javascript
    id: forwarded_hostname
    source: >
      function process(event) {
        var channel = event.Get("winlog.channel");
        if channel && channel === "ForwardedEvents" {
          event.Put("host.name" , event.Get("winlog.computer_name"));
        }
      }

```

---

<div class="post-metadata">

**Author:** ![smerzlyakov](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Post date:** [September 11, 2019, 5:05pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/13 "2019-09-11T17:05:41Z")

</div>

Thanks for an example. Add some lines to move host field to observer.

```
processors:
  - script:
    lang: javascript
    id: forwarded_hostname
    source: >
      function process(event) {
        var channel = event.Get("winlog.channel");
        if channel && channel === "ForwardedEvents" {
          event.Put("observer.hostname" , event.Get("host.name"));
          event.Put("observer.type" , "forwarder");
          event.Put("host.name" , event.Get("winlog.computer_name"));
        }
      }
```

---

<div class="post-metadata">

**Author:** ![smerzlyakov](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Post date:** [September 12, 2019, 9:28am UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/14 "2019-09-12T09:28:56Z")

</div>

> [@cwurm](#):
>
> processors: - script: lang: javascript id: forwarded\_hostname source: \> function process(event) { var channel = event.Get("winlog.channel"); if channel && channel === "ForwardedEvents" { event.Put("host.name" , event.Get("winlog.computer\_name")); } }

Hello! I have tested it now and it doesn't work. I get an error when start winlogbeat (7.1.1 version)  
I try my and yours variants. But it works without "processors" block.  
 ![fa9e-7e60-e47a-5733](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7be4672740daa26007788579a006a1d332eb4e83.png)

It is full config:

```
winlogbeat.event_logs:
  - name: ForwardedEvents
    forwarded: true
    ignore_older: 168h

processors:
  - script:
    lang: javascript
    id: forwarded_hostname
    source: >
      function process(event) {
        var channel = event.Get("winlog.channel");
        if channel && channel === "ForwardedEvents" {
          event.Put("host.name" , event.Get("winlog.computer_name"));
        }
      }

output.logstash:
  hosts: ["skynet-elk-8.i:5045"]

```

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [September 13, 2019, 10:07am UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/15 "2019-09-13T10:07:11Z")

</div>

@smerzlyakov Sorry, the `script` processor was added in 7.2.0 so is not yet available in your version. Can you use a newer version?

---

<div class="post-metadata">

**Author:** ![smerzlyakov](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Post date:** [September 16, 2019, 1:57pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/16 "2019-09-16T13:57:59Z")

</div>

In theory yes, but it a little bit difficult. I need to read all migration guides and i think ECS is changed, so i will have troubles with indexes.  
Is there another option?If no, i will try to begin update process. By the way, can you give me a link how to prepare for upgrading?

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [September 16, 2019, 2:25pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/17 "2019-09-16T14:25:58Z")

</div>

@smerzlyakov In general, we try to maintain backwards compatibility between minor releases. The [release notes](https://www.elastic.co/guide/en/beats/libbeat/7.2/release-notes-7.2.0.html) have very few changes for Winlogbeat between 7.1 and 7.2 so it most likely should not be a problem. But always good to test, you could run them side-by-side for a while and check for any differences in the data e.g. number of documents and some spot checks of some documents.

We actually don't backport bugfixes to older minors of a major (so there most likely won't be a 7.1.2 bugfix release), so I would recommend going to 7.3.2.

The ["upgrade guide"](https://www.elastic.co/guide/en/beats/libbeat/7.3/upgrading-minor-versions.html) for upgrading between minor versions is very simple: `upgrade [...] by simply installing the new release and restarting the Beat process`. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2019, 2:26pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162/18 "2019-10-14T14:26:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
