# Set custom ID for elastic-agent

**URL:** <https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419>\
**Category:** Endpoint Security\
**Created:** [August 24, 2021, 11:19pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419 "2021-08-24T23:19:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [August 24, 2021, 11:19pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/1 "2021-08-24T23:19:30Z")

</div>

Hello,

Is it possible to set or create a custom agent.id during or after the elastic-agent install, whether it be via a command line argument or an API call we can make?

For example, instead of `agent.id` being a uuid like `e9cdb5af-1585-4646-abad-4895668bb5cb` could we instead make it into a custom base64 encoded value?

Thanks

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [August 25, 2021, 7:06pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/2 "2021-08-25T19:06:56Z")

</div>

Hi @bm11100

No that isn't a supported feature.

---

<div class="post-metadata">

**Author:** ![mukeshelastic](https://avatars.discourse-cdn.com/v4/letter/m/e9a140/32.png) [@mukeshelastic](https://discuss.elastic.co/u/mukeshelastic)\
**Post date:** [August 25, 2021, 9:24pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/3 "2021-08-25T21:24:24Z")

</div>

@bm11100 are you able to elaborate on why you want to do that?

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [August 25, 2021, 9:40pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/4 "2021-08-25T21:40:54Z")

</div>

@mukeshelastic it doesn't necessarily have to be `agent.id`.

It could be ANY custom field that would be in all Endpoint documents, for something like `org.id` or `org`, or anything like that which could be configured dynamically at install/runtime or via an API.

There's a bunch of additional fields I'd need to track which isn't a good fit for namespaces or policy names.

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [August 26, 2021, 2:19pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/5 "2021-08-26T14:19:38Z")

</div>

> [@bm11100](#):
>
> It could be ANY custom field that would be in all Endpoint documents

What about `host.hostname`?

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [August 26, 2021, 2:39pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/6 "2021-08-26T14:39:46Z")

</div>

@gabriel.landau interesting, so you are thinking use `host.name` which then leaves `host.hostname` as a duplicative value that we could populate with custom info?

That would work, in theory, but how would we go about populating that dynamically at install? Or were you thinking API call after the fact?

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [August 26, 2021, 3:19pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/7 "2021-08-26T15:19:05Z")

</div>

> [@bm11100](#):
>
> @gabriel.landau interesting, so you are thinking use `host.name` which then leaves `host.hostname` as a duplicative value that we could populate with custom info?

Sorry I should have been clearer. Elastic Endpoint populates [host.hostname](https://github.com/elastic/endpoint-package/blob/ecb5dc6241321bdce75867dfd2f32755ebb75e21/schemas/v1/process/process.yaml#L878-L889) with the machine's host name, which is a value you can control.

---

<div class="post-metadata">

**Author:** ![mukeshelastic](https://avatars.discourse-cdn.com/v4/letter/m/e9a140/32.png) [@mukeshelastic](https://discuss.elastic.co/u/mukeshelastic)\
**Post date:** [August 30, 2021, 7:17pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/8 "2021-08-30T19:17:56Z")

</div>

@bm11100 Is this specific metadata that you want to add to some agents in a single agent policy? For example, you have a single agent policy that includes endpoint agents deployed on laptops of org1, org2 and then you want to add org as a metadata key and assign values org1 to laptops of org1 and similar for org2. Either at install time or after it has been installed through some api call.

If yes, we don't support that yet but it would be great if you could file an enhancement [Issues · elastic/beats · GitHub](https://github.com/elastic/beats/issues)

Today, the only way you could do that is by create different agent policies per org and including them in policy name or provide org names in namespaces when you create agent policies.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2021, 7:18pm UTC](https://discuss.elastic.co/t/set-custom-id-for-elastic-agent/282419/9 "2021-09-27T19:18:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
