# Wrong filebeat hostname in logs

**URL:** <https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 13, 2019, 6:37pm UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080 "2019-08-13T18:37:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sjorda20](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@sjorda20](https://discuss.elastic.co/u/sjorda20)\
**Post date:** [August 13, 2019, 6:37pm UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080/1 "2019-08-13T18:37:14Z")

</div>

I have 100 systems that are sending rsyslog messages to a syslog server.  
I have installed the ELK stack and filebeats on that server.

Filebeats is configured to monitor the logs that are being populated by syslog and send to the ELK stack.  
Here is the filebeat.input section:

#=========================== Filebeat inputs =============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

- type: log

* * *

When looking at logs in kibana, all logs, regardless of what client sent them, have the same host.name .  
In this case chiops

host.name chiops

* * *

chiops is the name of the syslog server and its also the ELK stack server.  
The 'message' part of the log entry in Kibana shows the actual client IP address

For example:  
message Aug 12 14:58:50 192.168.2.1 miniupnpd[778]: HTTP Connection from 192.168.2.248 closed unexpectedly

I would like to see the IP address of the actual client that sent the log and not the host servers name. as the host.name and not the server.

Can someone advise on how to configure this?

* * *

Here is my logstash configuration :

input {  
beats {  
port =\> 5044  
}  
}

filter {  
mutate {  
add\_field =\> { "remote\_ip" =\> "%{[@metadata][ip\_address]}" }  
}  
if [fileset][module] == "system" {  
if [fileset][name] == "auth" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostnam$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostnam$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostnam$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostnam$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostnam$  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostnam$  
pattern\_definitions =\> {  
"GREEDYMULTILINE"=\> "(.|\n)_"  
}  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
geoip {  
source =\> "[system][auth][ssh][ip]"  
target =\> "[system][auth][ssh][geoip]"  
}  
}  
else if [fileset][name] == "syslog" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[syst$  
pattern\_definitions =\> { "GREEDYMULTILINE" =\> "(.|\n)_" }  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 14, 2019, 9:42am UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080/2 "2019-08-14T09:42:03Z")

</div>

Please use the `</>` button in the editor window to format logs and configs.

Filebeat does not parse the syslog messages, but forwards lines found in the files as is. Filebeat adds some metadata to events, like the host name the event was collected from. As you send your events via logstash and all parsing happens within logstash, you might want to adapt your logstash filters to overwrite `host.name`.

---

<div class="post-metadata">

**Author:** ![sjorda20](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@sjorda20](https://discuss.elastic.co/u/sjorda20)\
**Post date:** [August 20, 2019, 4:46pm UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080/3 "2019-08-20T16:46:10Z")

</div>

Thanks! That was very helpful.  
Do you have a sample or example logstash filter configuration that shows how to have logstash overwrite host.name?

---

<div class="post-metadata">

**Author:** ![sjorda20](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@sjorda20](https://discuss.elastic.co/u/sjorda20)\
**Post date:** [August 22, 2019, 4:17pm UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080/4 "2019-08-22T16:17:07Z")

</div>

Thanks! That was very helpful.  
Does anyone have a sample or example logstash filter configuration that shows how to have logstash overwrite host.name?

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [August 29, 2019, 6:44pm UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080/5 "2019-08-29T18:44:12Z")

</div>

![grok_pattern](https://us1.discourse-cdn.com/elastic/original/3X/3/6/365d60548828fafa91b572ffbb46a903e81dda94.png)

Please test your message and grok pattern : [http://grokdebug.herokuapp.com](http://grokdebug.herokuapp.com)

Then you can use it in Filebeat input-\>processors  
([https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html))

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2019, 6:52pm UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080/6 "2019-09-26T18:52:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
