# Lowercase host.name FQDN Beta Fleet policy setting

**URL:** <https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047>\
**Category:** Kibana\
**Created:** [May 23, 2024, 7:59am UTC](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047 "2024-05-23T07:59:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 23, 2024, 7:59am UTC](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047/1 "2024-05-23T07:59:05Z")

</div>

Hello,

We are working through an effort to make sure `host.name` is indexed as lowercase fqdn everywhere. We put the original hostname in `host.hostname`.

Considering we have multiple domains, this is not only necessary to avoid host collision problems, but it also allows us to correlate host datasets with network datasets. We have 200+ datasets and some of them are logging camelcase, other uppercase, others lowercase, so there is also a requirement to lowercase the `host.name` everywhere.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4484c1ba5330d25eb4e71b63fb287583cc40590.png)

[Host Fields | Elastic Common Schema (ECS) Reference [8.11] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-host.html)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff59987eab17a4eb9ccf0b8738a73e85e3d84fa2.png)

But the Host Name format is still showing as Beta in the Fleet policy settings. Is there a plan to make it GA and also update the example to lowercase + effectively lowercase the host name value?

Thanks.

WillemD

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [May 23, 2024, 3:07pm UTC](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047/2 "2024-05-23T15:07:24Z")

</div>

Hi,

maybe you can use a `lowercase` processor in an Elasticsearch ingest pipeline to convert the `host.name` field to lowercase.

Regards

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 23, 2024, 3:23pm UTC](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047/3 "2024-05-23T15:23:36Z")

</div>

Hi @yago82

Everything can be custom made, but the feature exists .. in Beta. ECS says its the recommended value. We would like to see this become ga and supported so this can be a part of our long term logging and correlation strategy.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [May 23, 2024, 3:37pm UTC](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047/4 "2024-05-23T15:37:51Z")

</div>

Hi,

thank you for the clarification

Regards
