# Logstash to override meta information

**URL:** <https://discuss.elastic.co/t/logstash-to-override-meta-information/157078>\
**Category:** Logstash\
**Created:** [November 16, 2018, 2:02pm UTC](https://discuss.elastic.co/t/logstash-to-override-meta-information/157078 "2018-11-16T14:02:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kathir\_J](https://avatars.discourse-cdn.com/v4/letter/k/e47774/32.png) [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Post date:** [November 16, 2018, 2:02pm UTC](https://discuss.elastic.co/t/logstash-to-override-meta-information/157078/1 "2018-11-16T14:02:41Z")

</div>

I have a scenario where logs are created in one machine(say machine A) and sent to another machine(Say machine B) where I execute filebeat to push logs to elasticsearch).

When I try to execute filebeat, it gets the host name as machine B name(which is obviously valid though) and the same is getting visualised in Kibana.

What I want to know is, Is there a way that I can override [beat] [name] or [host] [name] in logstash config so that it sends the host name as machine A?  
I tried the below in logstash pipeline but no luck.

mutate { replace =\> { '[beat][hostname]' =\> "%{[obj][val]}" } }

---

<div class="post-metadata">

**Author:** ![Kathir\_J](https://avatars.discourse-cdn.com/v4/letter/k/e47774/32.png) [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Post date:** [November 28, 2018, 12:44pm UTC](https://discuss.elastic.co/t/logstash-to-override-meta-information/157078/2 "2018-11-28T12:44:51Z")

</div>

> [@Kathir\_J](#):
>
> t I want to know is, Is there a way that I can override [beat] [name] or [host] [name] in logstash config so that it sends the host name as machine A?  
> I tried the below in logstash pipeline but no luck.
> 
> mutate { replace =\> { '[beat][hostname]' =\> "%{[obj][val]}" } }

Any reply would be highly appreciated.

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 28, 2018, 1:41pm UTC](https://discuss.elastic.co/t/logstash-to-override-meta-information/157078/3 "2018-11-28T13:41:47Z")

</div>

What you are trying to do should work:

```
mutate { replace => { "[beat][hostname]" => "machine_A" } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2018, 1:41pm UTC](https://discuss.elastic.co/t/logstash-to-override-meta-information/157078/4 "2018-12-26T13:41:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
