# How to correctly report VM hostname when Elastic Agent runs in a Podman container

**URL:** <https://discuss.elastic.co/t/how-to-correctly-report-vm-hostname-when-elastic-agent-runs-in-a-podman-container/383336>\
**Category:** Elastic Agent\
**Tags:** filebeat, auditbeat\
**Created:** [November 10, 2025, 2:47pm UTC](https://discuss.elastic.co/t/how-to-correctly-report-vm-hostname-when-elastic-agent-runs-in-a-podman-container/383336 "2025-11-10T14:47:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [November 10, 2025, 2:47pm UTC](https://discuss.elastic.co/t/how-to-correctly-report-vm-hostname-when-elastic-agent-runs-in-a-podman-container/383336/1 "2025-11-10T14:47:28Z")

</div>

Hi everyone,

I’m trying to collect **package installation/removal events** using the system\_audit.package stream on **Rocky Linux 9.6**.

I’m running **Elastic Agent 9.1.3 (elastic-agent-complete)** inside a **Podman container** , managed via **podman-compose**.

Image: `docker.elastic.co/elastic-agent/elastic-agent-complete:9.1.3`

I’m using the **Kibana System Audit Integration v1.11.0**.

**Context**

In this setup, the ingested logs **have identical values for host.name, host.hostname, and agent.name** — all matching the **container name**.

However, these containers are actually collecting audit data **from the host VM** , so I’d like to include an **identifier of that**  **VM** (not the container).

Could you please advise which **ECS field** would be most appropriate for that purpose?

Is it recommended to overwrite host.name / host.hostname with the VM’s name, or should I use a different field instead?

### **What I’ve tried**

Mounting /etc/hostname → /etc/hostname

- → The agent didn’t seem to use it.

- Setting an environment variable with the host’s name and adding processors:

```auto
processors:
  - add_fields:
      target: host
      fields:
        name: "somehostname"
        hostname: "somehostname"

```

But the agent still overwrote these fields internally.

For now, I’ve worked around this using a @custom **ingest pipeline** in Elasticsearch that replaces the values after ingestion, but I’d much prefer a clean solution directly on the **agent level** if possible.

Any guidance or best practices on how to handle this would be greatly appreciated 🙂  
Thanks!

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [November 12, 2025, 11:56am UTC](https://discuss.elastic.co/t/how-to-correctly-report-vm-hostname-when-elastic-agent-runs-in-a-podman-container/383336/2 "2025-11-12T11:56:23Z")

</div>

Turns out the solution was pretty simple — since the setup uses **Jinja2** and **Ansible** , I just set this in the podman-compose file:

```auto
services:
  elastic-agent:
    hostname: "{{ inventory_hostname }}"

```
