# Number of hosts displayed in Kibana dashboard (is wrong)

**URL:** https://discuss.elastic.co/t/number-of-hosts-displayed-in-kibana-dashboard-is-wrong/196256
**Category:** Kibana
**Created:** [August 22, 2019, 7:25am UTC](https://discuss.elastic.co/t/number-of-hosts-displayed-in-kibana-dashboard-is-wrong/196256 "2019-08-22T07:25:05Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![JustinJ](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@JustinJ](https://discuss.elastic.co/u/JustinJ)
#### Post date: [August 22, 2019, 7:25am UTC](https://discuss.elastic.co/t/number-of-hosts-displayed-in-kibana-dashboard-is-wrong/196256/1 "2019-08-22T07:25:05Z")

</div>

In my cluster configuration, I have two ingest nodes, two data node and 1 kibana(coordinate node). Also, i have configured a central event collector in Windows server 2016 and installed winlog beat and filebeat on the same server. clients push event logs to this windows server. which is further forwarded to the elasticsearch by the beat clients. In kibana, only the central event collector is shown as hosts. Can we change it somehow to show the actual number of hosts from which the logs are collected.

---

<div class="post-metadata">

### Author: ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)
#### Post date: [August 22, 2019, 4:37pm UTC](https://discuss.elastic.co/t/number-of-hosts-displayed-in-kibana-dashboard-is-wrong/196256/2 "2019-08-22T16:37:39Z")

</div>

I believe you may need to change the visualization(s) to use the `winlog.computer_name` field. [https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-winlog.html#\_winlog](https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-winlog.html#_winlog)

---

<div class="post-metadata">

### Author: ![JustinJ](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@JustinJ](https://discuss.elastic.co/u/JustinJ)
#### Post date: [August 25, 2019, 5:27am UTC](https://discuss.elastic.co/t/number-of-hosts-displayed-in-kibana-dashboard-is-wrong/196256/3 "2019-08-25T05:27:37Z")

</div>

Thanks. That should work. I changed for filebeat and now SIEM shows correct number of linux hosts.

---

<div class="post-metadata">

### Author: ![JustinJ](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@JustinJ](https://discuss.elastic.co/u/JustinJ)
#### Post date: [August 25, 2019, 5:31am UTC](https://discuss.elastic.co/t/number-of-hosts-displayed-in-kibana-dashboard-is-wrong/196256/4 "2019-08-25T05:31:16Z")

</div>

Is there any way we can add the ip address also. In windows events, ip address field is empty. It is only having hostname. Is there any way we can parse the ip address using the hostname and add it to the forwarded log using winlogbeat.

Please note all out client is agentless. Windows clients are forwarding logs to a central log collector where winlogbeat is installed. Winlogbeat is forwarding these logs to the elasticsearch.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 22, 2019, 5:31am UTC](https://discuss.elastic.co/t/number-of-hosts-displayed-in-kibana-dashboard-is-wrong/196256/5 "2019-09-22T05:31:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
