# Putting add\_host\_metadata per input

**URL:** <https://discuss.elastic.co/t/putting-add-host-metadata-per-input/232098>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 11, 2020, 7:02pm UTC](https://discuss.elastic.co/t/putting-add-host-metadata-per-input/232098 "2020-05-11T19:02:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 11, 2020, 7:02pm UTC](https://discuss.elastic.co/t/putting-add-host-metadata-per-input/232098/1 "2020-05-11T19:02:17Z")

</div>

Hello,

Is it possible to add the add\_host\_metadata processor in filebeat.yml for specific inputs only?

This works:

```
filebeat.inputs:
- type: log
  paths: C:\Windows\System32\LogFiles\Firewall\*.log
  pipeline: filebeat-windows-firewall
  
- type: syslog
  protocol.udp:
    max_message_size: 25KiB
    host: "192.168.1.102:1514"
  pipeline: filebeat-pfsense
  processors:
  - add_observer_metadata:
      cache.ttl: 5m
      geo:
        name: pfsense.domain.lan
        location: 41.031833, 3.728900
        continent_name: Europe
        country_iso_code: BE
        region_name: Oost-Vlaanderen
        region_iso_code: OVL
        city_name: Ghent
        
processors:
- add_host_metadata:
    netinfo.enabled: true

```

But this does not:

```
filebeat.inputs:
- type: log
  paths: C:\Windows\System32\LogFiles\Firewall\*.log
  pipeline: filebeat-windows-firewall
  processors:
  - add_host_metadata:
      netinfo.enabled: true  

- type: syslog
  protocol.udp:
    max_message_size: 25KiB
    host: "192.168.1.102:10514"
  pipeline: filebeat-pfsense
  processors:
  - add_observer_metadata:
      cache.ttl: 5m
      geo:
        name: pfsense.domain.lan
        location: 41.031833, 3.728900
        continent_name: Europe
        country_iso_code: BE
        region_name: Oost-Vlaanderen
        region_iso_code: OVL
        city_name: Ghent

```

As you can see I want the pfsense input to only have the observer fields, while the Windows firewall logs should only have the host fields.

Filebeat is not starting with the last config. It's weird, because I'm doing similar stuff on Winlogbeat where this does seem to work.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2020, 7:02pm UTC](https://discuss.elastic.co/t/putting-add-host-metadata-per-input/232098/2 "2020-06-08T19:02:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
