Beats input is stripping domain name


#1

Hi Jochen and team:

I am testing Filebeat as a replacement for NXlog for inputting text files. I have setup a Beats input for Graylog, and it is receiving from my text file properly. So far so good.

The only problem is that the entries I see coming into Graylog have stripped down the hostname: they have removed the domain name. For example: In Graylog I would expect to see ‘machine1.mydomain.com’, but these log entries are simply from ‘machine1’.

Without using an extractor is there anyway to get the Beats input to display full hostnames like all my other inputs do?


(Jochen) #2

The Beats input is using the beat.hostname field from the Beats messages sent by Filebeat (or any other Beat).
https://www.elastic.co/guide/en/beats/filebeat/6.3/exported-fields-beat.html#exported-fields-beat


Maybe you can configure the hostname of your system correctly. You can check the hostname with the hostname(1) command.


#3

Hmm… when you run ‘hostname’ on Windows (Win10) it does not echo the full hostname with domain like it does when you run it on Linux (CentOS). I will find a workaround.

Thanks again


(system) #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.