# Searching logs by host name

**URL:** <https://discuss.elastic.co/t/searching-logs-by-host-name/316388>\
**Category:** Kibana\
**Tags:** ecs-elastic-common-schema\
**Created:** [October 12, 2022, 12:16am UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388 "2022-10-12T00:16:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [October 12, 2022, 12:16am UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/1 "2022-10-12T00:16:13Z")

</div>

I have a little quandary. I'd like my customers to easily search for logs by host name. ECS has a field, `host.name` exactly for that information, but it's _ **keyword** _, and that requires users know the exact capitalization and full name (which is sometimes hard to remember, like "DC1-ABcd99").

Is there a way I can continue to maintain ECS compatibility by keeping the field a keyword, but enable easier querying ("full text" I guess) for customers in Kibana?

---

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [October 12, 2022, 4:13pm UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/2 "2022-10-12T16:13:11Z")

</div>

I can see there are many posts about how to do case insensitive searches.

My question is can I keep the field as keyword _and_ enable easier searching in the UI, with lowercase and partial matching?

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [October 12, 2022, 7:51pm UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/3 "2022-10-12T19:51:17Z")

</div>

One option is creating a [multi-field](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html#_multi_fields_with_multiple_analyzers) of type `text` for the `host.name` field. Some ECS fields, like [`process.name`](https://www.elastic.co/guide/en/ecs/current/ecs-process.html#field-process-name), follow this convention and also define `process.name.text`.

`host.name` would remain a `keyword` field, and `host.name.text` would be the multi-field. Since `host.name.text` is indexed as type `text`, case insensitive search is supported.

Another option: some term-level query types, like [wildcard](https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-wildcard-query.html#wildcard-query-field-params), support a `case_insensitive` argument. Setting `case_insensitive: true` allows case-insensitive search against `keyword` fields for the supported query types.

---

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [October 17, 2022, 5:42pm UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/4 "2022-10-17T17:42:37Z")

</div>

I like having a multi-field to make text searching easier, thanks for the idea.

Is there a way to have Kibana search `host.name.text` in addition to `host.name` when my customers search in Kibana for, say, `host.name:dc1`? I want to try to make it as easy as possible for them and not have to educate them about keyword fields (but I do want to try to stick to ECS).

Is the solution to have my customers always search `host.name.text` instead?

---

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [October 19, 2022, 2:38am UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/5 "2022-10-19T02:38:26Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/3/239edeb7a1d6b25fae04dcd168596881c592fffe.png)

I can see for some fields Kibana recognizes them as multi-fields, but when I add a `host.name.text` multi-field, its parent `host.name` doesn't show up as having a multi-field.

I don't see any real difference in the index mappings:

```auto
"process": {
  "properties": {
    "executable": {
      "type": "text",
      "fields": {
        "keyword": {
          "type": "keyword",
          "ignore_above": 256

```

v.

```auto
"host": {
  "properties": {
    "name": {
      "type": "keyword",
      "fields": {
        "text": {
          "type": "text"

```

---

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [October 25, 2022, 9:31pm UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/6 "2022-10-25T21:31:18Z")

</div>

By the way, I missed this documentation earlier that says **using text multi-fields is a blessed convention** :

> **[Conventions | Elastic Common Schema (ECS) Reference \[8.4\] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-conventions.html#_ecs_convention_for_indexing_text_fields)**

---

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [November 15, 2022, 12:12am UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/7 "2022-11-15T00:12:19Z")

</div>

I'm still unable to get `host.name` to act as a multi-field.

I turned on Kibana's display of multi-fields so I can see, in another index/index pattern, that `process.executable` for example has a multi-field companion `process.executable.keyword`, and they're **both** marked as multi-fields:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8bb12519f4efbd32c00890aebea48a02ce093006.png)

But in this index/index pattern with field `host.name`, despite having created [the same mapping arrangement](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/5) as with `process.executable` / `process.executable.keyword`, the primary field does not show as a multi-field:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/0/904e41ed039203abcc8054ee47766c310712cfd4.png)

I'm left thinking that it's not just the mapping arrangement that needs to be correct, but something else too?

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [November 16, 2022, 4:33pm UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/8 "2022-11-16T16:33:31Z")

</div>

After making the changes to your mappings, did you refresh your Kibana data views/index patterns? I'd give it a try to see if afterwards Kibana picks up the mapping change to what's expected.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2022, 4:33pm UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/9 "2022-12-14T16:33:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
