# Where is the object mapping for \[host\] defined?

**URL:** <https://discuss.elastic.co/t/where-is-the-object-mapping-for-host-defined/281541>\
**Category:** Elasticsearch\
**Tags:** ecs-elastic-common-schema\
**Created:** [August 16, 2021, 12:07pm UTC](https://discuss.elastic.co/t/where-is-the-object-mapping-for-host-defined/281541 "2021-08-16T12:07:49Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![antoineco](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antoineco/32/93214_2.png) [@antoineco](https://discuss.elastic.co/u/antoineco)\
**Post date:** [August 16, 2021, 1:10pm UTC](https://discuss.elastic.co/t/where-is-the-object-mapping-for-host-defined/281541/7 "2021-08-16T13:10:11Z")

</div>

The data I'm sending is not structured and does not contain any `host` field. This field is injected by Logstash's [TCP input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html).

The behaviour is documented and well understood. Like I said, what I _don't_ understand is what specific behaviour of Elasticsearch prevents the injection of this field, not where the field is coming from.

As a workaround, I'm simply renaming the field in my pipeline as follows, but I'm still a bit frustrated not to be able to find out the source of the issue.

```ruby
filter {
    if [host] and ![host][name] {
        mutate {
            rename => { "[host]" => "[host][name]" }
        }
    }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/where-is-the-object-mapping-for-host-defined/281541)._
