# Hosts table : host.name (alias of beat.name) used instead of agent.hostname

**URL:** <https://discuss.elastic.co/t/hosts-table-host-name-alias-of-beat-name-used-instead-of-agent-hostname/219088>\
**Category:** SIEM\
**Created:** [February 12, 2020, 10:08pm UTC](https://discuss.elastic.co/t/hosts-table-host-name-alias-of-beat-name-used-instead-of-agent-hostname/219088 "2020-02-12T22:08:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Georgios\_Gkinis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgios_gkinis/32/47225_2.png) [@Georgios\_Gkinis](https://discuss.elastic.co/u/Georgios_Gkinis)\
**Post date:** [February 12, 2020, 10:08pm UTC](https://discuss.elastic.co/t/hosts-table-host-name-alias-of-beat-name-used-instead-of-agent-hostname/219088/1 "2020-02-12T22:08:35Z")

</div>

I am using beats to forward metrics and logs to Elasticsearch.  
In the configuration of each beat I have setup its name manually :

`name: "${COMPUTERNAME}-filebeat-applications"`

When I go to SIEM -\> Hosts -\> table All Hosts I have a line for **each beat** instead of each _host_. (12 hosts instead of the actual 3)

After inspecting the request I see that the aggregation is performed on the **host.name** field :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/b/abdf9b52fcbab6135fa990ea7c07ccc4e7b0c8b9.png)

```auto
{
  "aggregations": {
    "host_count": {
      "cardinality": {
        "field": " **host.name**"
      }
    },
    "host_data": {
      "terms": {
        "size": 10,
        "field": " **host.name**",
        "order": {
          "lastSeen": "desc"
        }
      },

```

According to the [filebeat reference](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-beat-common.html) the **host.name** field is an alias of **beat.name** which I have changed manually.

I suppose this could be fixed by changing the alias **host.name** to point to **agent.hostname** to fix this but then I use a modified ECS template which beats the purpose.

Another fix could be to just query for agent.hostname from SIEM, although I suspect that it could break when data is not shipped by a beat.

Any suggestions on a workaround and a possible fix?

Thanks,

George.

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [February 17, 2020, 8:10pm UTC](https://discuss.elastic.co/t/hosts-table-host-name-alias-of-beat-name-used-instead-of-agent-hostname/219088/2 "2020-02-17T20:10:19Z")

</div>

Hi George,  
I'm afraid we've caused some confusion with our documentation and some unexpected field population. I've created a beats issue to get to the bottom of this [here](https://github.com/elastic/beats/issues/16377).

By design, `host.name` is the field used by the SIEM app to identify hosts, and as you discovered, is used in the aggregations that populate certain host widgets in the SIEM app. This field is defined in Elastic Common Schema [here](https://www.elastic.co/guide/en/ecs/current/ecs-host.html).

In order for your events to be displayed properly in SIEM app host views, the `host.name` field must be populated properly. Normally, you should not have to do anything special to make this happen, since if you've set up a Filebeat module, the add\_host\_metadata processor will populate that field for you by default.

However, in your case, it appears that the value you've set for `name:` in your beats configuration files is unexpectedly populating the `host.name` field in your events, causing the host displays to be incorrect.

**Workaround** :  
As a solution or workaround, you can remove the setting of `name:` from your beats configs, and then the hosts should be displayed properly in the SIEM app. If you want to filter on the beat, you can use the ECS field `agent.type` which is also populated by default, in your case with "filebeat"

Note: We do not recommend building dependence upon the `agent.hostname` field, as this is not an ECS-defined field, and it's continued use in the future is not certain.

Please let us know if this helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2020, 8:10pm UTC](https://discuss.elastic.co/t/hosts-table-host-name-alias-of-beat-name-used-instead-of-agent-hostname/219088/3 "2020-03-16T20:10:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
