Capture environment variablesedit

You can configure an Elastic Agent policy to capture up to five environment variables (env vars). Captured environment variables are associated with process events and recorded in the process.env_vars field.

  • Env var names must be no more than 63 characters, and env var values must be no more than 1023 characters. Values outside these limits are silently ignored.
  • Env var names are case sensitive in Linux.

To set up environment variable capture for an Elastic Agent policy:

  1. Go to Manage → Policies.
  2. Select an Elastic Agent policy.
  3. Click Show advanced settings.
  4. Scroll down or search for linux.advanced.capture_env_vars.
  5. Enter the names of env vars you want to capture, separated by commas. For example: PATH,LD_PRELOAD,USER
  6. Click Save.
The "linux.advanced.capture_env_vars" advanced agent policy setting