# Where to find information about field "application\_name"

**URL:** <https://community.graylog.org/t/where-to-find-information-about-field-application-name/17146>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [September 11, 2020, 1:48pm UTC](https://community.graylog.org/t/where-to-find-information-about-field-application-name/17146 "2020-09-11T13:48:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![seroal](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@seroal](https://community.graylog.org/u/seroal)\
**Post date:** [September 11, 2020, 1:48pm UTC](https://community.graylog.org/t/where-to-find-information-about-field-application-name/17146/1 "2020-09-11T13:48:42Z")

</div>

I am wondering about the field “application\_name”, that I have neither configured or created. It is filled with some input in some cases, that I do not understand. For me it seems, as if it is generated/filled by something like a graylog integrated feature. Is there a way to disable the processing for this field? Where can it be configured/adjusted or where do I find some more information about it?

Thanks.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [September 14, 2020, 7:27am UTC](https://community.graylog.org/t/where-to-find-information-about-field-application-name/17146/2 "2020-09-14T07:27:35Z")

</div>

It’s very obvious. If you use Syslog Input (TCP/UDP), graylog follows syslog standard and extract field application\_name from syslog message send by device.

There are 2 standards for Syslog protocol: Older RFC3164 and newer RFC5424.

Check some article about syslog:

> **[What is Syslog: Daemons, Message Formats and Protocols - Sematext](https://sematext.com/blog/what-is-syslog-daemons-message-formats-and-protocols/)**
>
> Last updated on Dec 10, 2017 Pretty much everyone’s heard about syslog: with its roots in the 80s, it’s still used for a lot of the logging done today. Mostly because of its long history, syslog is quite a vague \[…\]

If you don’t want to parse syslog messages at all, create Raw Input, which will store exact message as received. If you want to use another field as application\_name (as some devices like cisco doesn’t follow syslog standard), create extractor or use pipeline rule to fix it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 28, 2020, 7:27am UTC](https://community.graylog.org/t/where-to-find-information-about-field-application-name/17146/3 "2020-09-28T07:27:42Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
