you can use processors like Dissect for filebeat or metricbeat. This will add/modify the logs being stored into elasticsearch.
you can use Scripted field, this is on the fly hence no altering of logs but this is resource intensive on Kibana and might affect performance of Kibana.
If you have a logstash, it will be easier to filter with GROK, Dissect and etc. This will add/modify the logs being stored into elasticsearch.
hoat.hostname is populated by whatever is returned by the hostname command which is what's located in /etc/hostname. Is host.name populated? I would go with the dissect processor to generate the field u want from the fqdn as mentioned above.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.