# Why doesn't add\_tag =\> \["${HOSTNAME}"\] work?

**URL:** <https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366>\
**Category:** Logstash\
**Created:** [April 24, 2018, 6:36pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366 "2018-04-24T18:36:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 6:36pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/1 "2018-04-24T18:36:08Z")

</div>

This is an environment variable, but I can't get it to work? The tag save is, ${HOSTNAME}, not the environment variable value.

[https://www.elastic.co/guide/en/logstash/current/environment-variables.html#\_setting\_the\_value\_of\_a\_tag](https://www.elastic.co/guide/en/logstash/current/environment-variables.html#_setting_the_value_of_a_tag)

```
filter {  
  mutate {
    add_tag => ["${HOSTNAME}"]
  }
...
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 6:50pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/2 "2018-04-24T18:50:13Z")

</div>

How do you know the HOSTNAME variable is set? Have you inspected /proc/$LOGSTASH\_PID/environ?

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 6:55pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/3 "2018-04-24T18:55:38Z")

</div>

I am trying to use the environment variable that I can see with printenv.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 7:10pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/4 "2018-04-24T19:10:45Z")

</div>

Okay, but I'd still check what environment variables the actual Logstash process is seeing. Also, which version of Logstash is this?

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 7:12pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/5 "2018-04-24T19:12:04Z")

</div>

v6.2, and I don't see it in /proc/$LOGSTASH\_PID/environ.

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 7:14pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/6 "2018-04-24T19:14:03Z")

</div>

I'm really confused because this is used in the elasticsearch.yml, but doesn't work in logstash?

```
node.name: ${HOSTNAME}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 7:17pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/7 "2018-04-24T19:17:56Z")

</div>

elasticsearch.yml and Logstash pipeline configuration files are entirely different beast, but `${HOSTNAME}` should work if that environment variable is set, but it seems like it isn't. Are you starting Logstash from your shell or via an init script (or the systemd equivalent)?

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 7:19pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/8 "2018-04-24T19:19:33Z")

</div>

systemd:

systemctl start logstash

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 7:36pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/9 "2018-04-24T19:36:47Z")

</div>

Okay, but the environment variables are set completely differently in the systemd case. According to [https://superuser.com/questions/132489/hostname-environment-variable-on-linux](https://superuser.com/questions/132489/hostname-environment-variable-on-linux) `$HOSTNAME` is a bash invention.

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 7:42pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/10 "2018-04-24T19:42:29Z")

</div>

So, I looked in the elasticsearch-env file and saw, export HOSTNAME=$HOSTNAME, and I added it to logstash.lib.sh. It now shows in /proc/$LOGSTASH\_PID/environ correctly. But now logstash logs an error!

```
[root@LMUWU0438 bin]# cat /proc/5254/environ

HOSTNAME=LMUWU0438GEM_HOME=/usr/share/logstash/vendor/bundle/jruby/2.3.0SHELL=/sbin/nologinLS_GROUP=logstashLS_HOME=/usr/share/logstashLS_NICE=19LS_JVM_OPTS=/etc/logstash/jvm.optionsJAVA_OPTS=-Xms256m -Xmx1g -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+DisableExplicitGC -Djava.awt.headless=true -Dfile.encoding=UTF-8 -XX:+HeapDumpOnOutOfMemoryError USER=logstashSERVICE_DESCRIPTION=logstashPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/binLS_OPEN_FILES=16384PWD=/LS_SETTINGS_DIR=/etc/logstashLS_PIDFILE=/var/run/logstash.pidLANG=en_US.UTF-8SERVICE_NAME=logstashLS_USER=logstashSHLVL=0HOME=/opt/logstashLOGNAME=logstashLS_GC_LOG_FILE=/var/log/logstash/gc.logGEM_PATH=/usr/share/logstash/vendor/bundle/jruby/2.3.0JAVACMD=/bin/javaSINCEDB_DIR=/usr/share/logstashLOGSTASH_HOME=/usr/share/logstash
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 7:47pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/11 "2018-04-24T19:47:09Z")

</div>

> But now logstash logs an error!

Namely....?

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 7:58pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/12 "2018-04-24T19:58:53Z")

</div>

It's too big to paste here. Not sure how to post it here?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 8:02pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/13 "2018-04-24T20:02:25Z")

</div>

Use pastebin or a GitHub gist.

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 8:11pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/14 "2018-04-24T20:11:49Z")

</div>

I set logging to debug. (I fixed the link)

> <https://gist.github.com/jpeppercorn/f006a5405f0db63c07622d3849a2ed7b#file-gistfile1-txt>

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 8:53pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/15 "2018-04-24T20:53:25Z")

</div>

> [2018-04-24T16:04:50,977][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"Java::OrgLogstashSecretStore::SecretStoreException::AccessException", :message=\>"Could not determine keystore password. Please ensure the file at /etc/logstash/logstash.keystore is a valid Logstash keystore",  
> ...

It's not obvious why this would have anything to do with the addition of the HOSTNAME variable. Are you sure it only happens when you set it in logstash.lib.sh?

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 9:14pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/16 "2018-04-24T21:14:36Z")

</div>

No, it only happens when I have the mutate entry. I'm going to start logstash with debug logging without the mutate and put the log up.

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 24, 2018, 9:23pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/17 "2018-04-24T21:23:08Z")

</div>

Mutate is commented out. Runs fine.

> <https://gist.github.com/jpeppercorn/9df2f6d3b0a2e7188fe93472cec67a0a>

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 25, 2018, 12:07pm UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/18 "2018-04-25T12:07:52Z")

</div>

@magnusbaeck, FYI, when I run this pipeline locally, I get a different error!

I have created a support ticket, and once resolved will update here. Thank you for all of your help!

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 26, 2018, 12:44am UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/19 "2018-04-26T00:44:09Z")

</div>

@magnusbaeck, With the help of elastic support, we figured this out. Turns out it was 2 easy changes to get it working. I am not saying that it was easy figuring this out, because it wasn't easy!

```
mutate {
  add_tag => ["${HOSTNAME}"]
}

```

- Add xpack.management.pipeline.id: to logstash.yml
- Create file, /etc/sysconfig/logstash, (chmod 600) and add these 2 lines
  - HOSTNAME=ThisHostName
  - LOGSTASH\_KEYSTORE\_PASS=password

Thanks again for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2018, 12:44am UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366/20 "2018-05-24T00:44:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
