# Unable to rename host to \[host\]\[name\]

**URL:** <https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824>\
**Category:** Logstash\
**Created:** [April 13, 2020, 9:05pm UTC](https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824 "2020-04-13T21:05:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![boyhittscar](https://avatars.discourse-cdn.com/v4/letter/b/e9bcb4/32.png) [@boyhittscar](https://discuss.elastic.co/u/boyhittscar)\
**Post date:** [April 13, 2020, 9:05pm UTC](https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824/1 "2020-04-13T21:05:38Z")

</div>

Hello -

I feel like this should be easy, and I'm not really sure why this isn't working.

I have the following data  
host: MYPC  
endpoint\_type: computer

To follow ECS, I'm attempting to do a mutate and rename /nest the fields to  
host.name  
host.type

However - that appears to failed with the following

```auto
[2020-04-13T16:50:52,406][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"dev-2020.04.13", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x36df53bc>], :response=>{"index"=>{"_index"=>"dev-2020.04.13", "_type"=>"_doc", "_id"=>"LRRPdXEBiQpvxsQYIBFT", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [host] of type [text] in document with id 'xxxxxxxxxxxxx'. Preview of field's value: '{type=computer}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:844"}}}}}

```

I even tried dropping the field host to then rename (as there were prior contents in there) but that still didn't work.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 13, 2020, 10:42pm UTC](https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824/2 "2020-04-13T22:42:23Z")

</div>

In logstash that should be [host][name] and [host][type]. What does your mutate filter look like?

---

<div class="post-metadata">

**Author:** ![boyhittscar](https://avatars.discourse-cdn.com/v4/letter/b/e9bcb4/32.png) [@boyhittscar](https://discuss.elastic.co/u/boyhittscar)\
**Post date:** [April 14, 2020, 10:12am UTC](https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824/3 "2020-04-14T10:12:57Z")

</div>

Badger,

The filter has been the following. I've also tried without having the [host] fields enclosed in double quotes. Since that had caused an issue for me in an if statement.

```auto
      rename => { "host" => "[host][name]" }
      rename => { "endpoint_type" => "[host][type]" }

```

---

<div class="post-metadata">

**Author:** ![boyhittscar](https://avatars.discourse-cdn.com/v4/letter/b/e9bcb4/32.png) [@boyhittscar](https://discuss.elastic.co/u/boyhittscar)\
**Post date:** [April 15, 2020, 7:07pm UTC](https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824/4 "2020-04-15T19:07:59Z")

</div>

No matter how I re-work this cannot get it to set host.name.

I've tried rename, replace, and copy. As I'm working towards ECS compliance this has been the first big headache.

---

<div class="post-metadata">

**Author:** ![boyhittscar](https://avatars.discourse-cdn.com/v4/letter/b/e9bcb4/32.png) [@boyhittscar](https://discuss.elastic.co/u/boyhittscar)\
**Post date:** [April 16, 2020, 5:05pm UTC](https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824/5 "2020-04-16T17:05:17Z")

</div>

Not sure if it's a solution as much as it is a work around. But I got it working.

I was using the file input to bring in AV logs. The file input was setting "host" to the hostname of the logstash host, which was then preventing any renames to the host field.

I had to in it's own block before any parsing takes place remove the host and path field set by the logstash file input plugin.

```auto
   mutate {
      remove_field => ["host", "path"]
    }

```

Then in the following blocks the following worked:

```auto
      rename => { "host" => "[host][name]" }
      rename => { "endpoint_type" => "[host][type]" }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2020, 5:05pm UTC](https://discuss.elastic.co/t/unable-to-rename-host-to-host-name/227824/6 "2020-05-14T17:05:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
