# The Ingest Pipeline for 365 Defender doesn't populate hostname

**URL:** https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312
**Category:** Beats
**Tags:** filebeat
**Created:** [January 13, 2022, 6:37pm UTC](https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312 "2022-01-13T18:37:24Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![hinchliff](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hinchliff](https://discuss.elastic.co/u/hinchliff)
#### Post date: [January 13, 2022, 6:37pm UTC](https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312/1 "2022-01-13T18:37:24Z")

</div>

We're using the "Microsoft" module in Filebeat to collect data from Microsoft Defender -- both the "defender\_atp" and the "m365\_defender". We're also using the Ingest Pipelines provided via Filebeat to parse and process the events.

We have noticed that the (parsed) events from Defender ATP include the fields host.name and host.hostname, but these fields seem to be missing from the 365 Defender events.

Looking at the Ingest Pipeline for 365 Defender it seems to be doing this:

1. removing any 'host' field from the raw event
2. _not_ populating any host.name or host.hostname field
3. appending 'host.hostname' (which will never exist?) to the field 'related.hosts'

Compared to the Ingest Pipeline for Defender ATP, which seems to be doing this:

1. removing any 'host' field from the raw event
2. renaming the field 'json.computerDnsName' to 'host.hostname'
3. copying 'host.hostname' to 'host.name'
4. appending 'host.hostname' to 'related.hosts'

Is that a bug in 365 Defender, that it is not populating any host.name or host.hostname field? It looks like the field 'json.alerts.devices.deviceDnsName' could be used to provide the hostname, at least in most of the events that we see.

Or is there some other reason why the 365 Defender events do not include a hostname field?

---

<div class="post-metadata">

### Author: ![hinchliff](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hinchliff](https://discuss.elastic.co/u/hinchliff)
#### Post date: [January 25, 2022, 5:39pm UTC](https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312/2 "2022-01-25T17:39:51Z")

</div>

> <https://github.com/elastic/beats/issues/29859>
>
> \*\*Describe the enhancement:\*\*
> The events from Defender ATP include the fields \`…host.name\` and \`host.hostname\`, but these fields seem to be missing from the 365 Defender events.
> 
> 
> 
> \*\*Describe a specific use case for the enhancement or feature:\*\*
> In order to use Elastic Security, \`host.name\` is a required field (\[Elastic Security ECS field reference\](https://www.elastic.co/guide/en/security/current/siem-field-reference.html))
> 
> 
> \*\*Additional Details\*\*
> \* https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312
> 
> Is this a "bug", that \`host.name\` is missing? Or an enhancement request to add \`host.name\` ?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 22, 2022, 7:40pm UTC](https://discuss.elastic.co/t/the-ingest-pipeline-for-365-defender-doesnt-populate-hostname/294312/3 "2022-02-22T19:40:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
