# Macros available for identifying the logstash host

**URL:** <https://discuss.elastic.co/t/macros-available-for-identifying-the-logstash-host/94520>\
**Category:** Logstash\
**Created:** [July 25, 2017, 5:46pm UTC](https://discuss.elastic.co/t/macros-available-for-identifying-the-logstash-host/94520 "2017-07-25T17:46:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [July 25, 2017, 5:46pm UTC](https://discuss.elastic.co/t/macros-available-for-identifying-the-logstash-host/94520/1 "2017-07-25T17:46:18Z")

</div>

We have several logstash hosts that have the same config, and we like to add a field upon ingestion via the `input` to help us show which logstash host ingested each line. It helps us to do some graphing, mapping, and checking.

Right now, we have to hard set this as a field within the input (a la `add_field => { "logstash_host" => "logstash2" }`

Is there a way to do this with some sort of macro so that we can use the same input file across all of our logstash nodes? Would be nice if we could do something like `"%{IP}"` or `"%{LAST_OCTET}"` or something like that.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 26, 2017, 7:10am UTC](https://discuss.elastic.co/t/macros-available-for-identifying-the-logstash-host/94520/2 "2017-07-26T07:10:30Z")

</div>

You can reference environment variables in configuration files: [https://www.elastic.co/guide/en/logstash/current/environment-variables.html](https://www.elastic.co/guide/en/logstash/current/environment-variables.html)

Alternatively, if you're using a tool like Ansible, Chef, or Puppet to push your configuration (which you should) you can easily make a template out of the configuration file and have the tool in question insert the hostname.

---

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [July 26, 2017, 12:13pm UTC](https://discuss.elastic.co/t/macros-available-for-identifying-the-logstash-host/94520/3 "2017-07-26T12:13:03Z")

</div>

Gah!!! Magnus!! I forgot about this feature. Thank you so much for reminding me of it. This will allow us to do exactly what we want to do.

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2017, 12:13pm UTC](https://discuss.elastic.co/t/macros-available-for-identifying-the-logstash-host/94520/4 "2017-08-23T12:13:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
