# How Do I Change The Format Of A Metric/File Beat Log Field?

**URL:** <https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723>\
**Category:** Beats\
**Tags:** filebeat, metricbeat\
**Created:** [April 9, 2021, 3:12pm UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723 "2021-04-09T15:12:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![kss](https://avatars.discourse-cdn.com/v4/letter/k/a587f6/32.png) [@kss](https://discuss.elastic.co/u/kss)\
**Post date:** [April 9, 2021, 3:12pm UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/1 "2021-04-09T15:12:12Z")

</div>

I am using ElasticSearch **FileBeat** and **MetricBeat** to provide logging for my apps. I am using Grafana to visualize this log data.

I do have a question though regarding the **host.hostname** field....

This field is storing the hostname in the following format:

```
ip-10-109-4-123.us-west-2.compute.internal

```

I am wondering if if it possible to change this format so that it stores the hostname as follows:

```
ip-10-109-4-123

```

**Or,** can I add a new field to the this log record that is based on the hostname field but with the ".us-west-2.compute.internal" stripped off?

Thanks

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [April 11, 2021, 6:19pm UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/2 "2021-04-11T18:19:42Z")

</div>

Hi Kss,

I know of few ways to do it:

1. you can use processors like Dissect for [filebeat](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html) or [metricbeat](https://www.elastic.co/guide/en/beats/metricbeat/current/dissect.html). This will add/modify the logs being stored into elasticsearch.
2. you can use [Scripted field](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html), this is on the fly hence no altering of logs but this is resource intensive on Kibana and might affect performance of Kibana.
3. If you have a logstash, it will be easier to filter with GROK, Dissect and etc. This will add/modify the logs being stored into elasticsearch.

Hope this helps you!

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 12, 2021, 12:26am UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/3 "2021-04-12T00:26:33Z")

</div>

`hoat.hostname` is populated by whatever is returned by the `hostname` command which is what's located in `/etc/hostname`. Is `host.name` populated? I would go with the dissect processor to generate the field u want from the fqdn as mentioned above.

---

<div class="post-metadata">

**Author:** ![kss](https://avatars.discourse-cdn.com/v4/letter/k/a587f6/32.png) [@kss](https://discuss.elastic.co/u/kss)\
**Post date:** [April 12, 2021, 9:38pm UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/4 "2021-04-12T21:38:29Z")

</div>

Thanks Kavier, I'll give Dissect a try. I tried scripted fields, but it doesn't look like I can access them with Grafana.

---

<div class="post-metadata">

**Author:** ![kss](https://avatars.discourse-cdn.com/v4/letter/k/a587f6/32.png) [@kss](https://discuss.elastic.co/u/kss)\
**Post date:** [April 12, 2021, 9:58pm UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/5 "2021-04-12T21:58:33Z")

</div>

I'm trying to get my brain around the syntax of dissect.

But first a question, does dissect create a new field, or does it operate on the source fields and modify it.

Second, what would the format be for the dissection. Based on the example in the doc this is what I'm coming up with.

Source string: ip-10-109-4-123.us-west-2.compute.internal  
(I want only ip-10-109-4-123)

Would the format be: "%{ipaddress}.%{region}.%{level2domain}.%{topleveldomain}"

Would this ADD the three fields to the document: ipaddress, region, level2domain and topleveldomain?

---

<div class="post-metadata">

**Author:** ![kss](https://avatars.discourse-cdn.com/v4/letter/k/a587f6/32.png) [@kss](https://discuss.elastic.co/u/kss)\
**Post date:** [April 12, 2021, 11:22pm UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/6 "2021-04-12T23:22:33Z")

</div>

This came in handy!  
[https://dissect-tester.jorgelbg.me/](https://dissect-tester.jorgelbg.me/)

---

<div class="post-metadata">

**Author:** ![kss](https://avatars.discourse-cdn.com/v4/letter/k/a587f6/32.png) [@kss](https://discuss.elastic.co/u/kss)\
**Post date:** [April 13, 2021, 3:22am UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/7 "2021-04-13T03:22:21Z")

</div>

Dissect works great. Thanks guys!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2021, 5:22am UTC](https://discuss.elastic.co/t/how-do-i-change-the-format-of-a-metric-file-beat-log-field/269723/8 "2021-05-11T05:22:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
