We are running +300 agents on Windows servers which have been setup using templated/automated installs. We now see that a lot of hosts share the same host.id value in our logging in Elastic which seems to be a problem when implementing the security rules, especially those that rely on patterns of consecutive events with the same host.id value.
What is a good way of moving forward? Can I alter the host.id? Does this have impact on other things? Any advice welcome.
I hope this helps. By altering the MachineGuid I could find a way to circumvent the duplicate host.id values. A solution could be a script that checks its hostname against a table of generated custom UUIDs and setting the corresponding MachineGuid to the matching value in the list. This way even for non-persistent VDIs there could be a way to have “persistent”, “unique” host.ids.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.