-
Notifications
You must be signed in to change notification settings - Fork 5k
Open
Labels
FilebeatFilebeatFilebeatFunctionbeatJournalbeatMetricbeatMetricbeatMetricbeatTeam:Elastic-Agent-Data-PlaneLabel for the Agent Data Plane teamLabel for the Agent Data Plane teamWinlogbeatdiscussionecslibbeat
Description
There are several use cases in Beats where the data reported by a Beat did not originate on that Beat host. Some examples are syslog, windows forwarded events, router netflow data, and cloud watch logs. In these cases it would be appropriate to set the host.*
field to information about the originating machine.
From ECS:
ECS host.* fields should be populated with details about the host on which the event happened, or from which the measurement was taken.
Some issues related to this:
- host.name behavior inconsistent across the Elastic stack #13777
- [winlogbeat] Use the original host for host.name in Windows Event Logs #13706
- [Filebeat] The host.name sent from Filebeat doesn't match the same field from Metricbeat #13589
- Not always send
host.name
and have host metadata processor enabled #10698
I think we need way for inputs and modules to be able to "designate" that host.*
should not be set by default. The output pipeline and also the add_host_metadata
processor will need to honor this "designation".
jsoriano, willemdh, Feder1co5oave, simitt, chicco27 and 4 more
Metadata
Metadata
Assignees
Labels
FilebeatFilebeatFilebeatFunctionbeatJournalbeatMetricbeatMetricbeatMetricbeatTeam:Elastic-Agent-Data-PlaneLabel for the Agent Data Plane teamLabel for the Agent Data Plane teamWinlogbeatdiscussionecslibbeat