Add IP-addresses and MAC-addresses to event

(Mathias Olsson) #1


I would like to dynamically add all IP-addresses and all MAC-addresses of the sender host to each event sent by filebeat. Is there a way to do that? If not, I would be happy to contribute a new processor, similar to the add_locale processor, but for this purpose.

(ruflin) #2

Hi @hypp

Interesting timing. We recently started a discussing about which additional host information we should add to an event for example through a processor. Can you open a feature request for this on Github and share some details on how you would implement and which field names you would use?

(Andrew Kroh) #3

I'm interested to know how this information would be used and why it's needed.

On a related note there was an enhancement to the logstash beats input to add [@metadata][ip_address] to all incoming events. So you could use this to add the source IP to events.

(Mathias Olsson) #4

I opened issue #5396 at Github for this. I hope that is what you wanted me to do?

(Mathias Olsson) #5

It will be used to track IP-address assignment over time for physical and virtual hardware,
for both statically assigned and dynamically assigned (DHCP) addresses.

(ruflin) #6

@hypp Thanks

(Steffen Siering) #7

Do we really need to add these kind of metadata to each single even from filebeat? Sounds more like a task for metricbeat (or another kind of beat) reporting some info on the hosts environment. For filebeat the issue is (on old logs or on back-pressure), the addresses do not necessarily match the time the log line was written.

(Mathias Olsson) #8

I definitely want it on every event, even though the data might be wrong in rare cases.
I suggest making it configurable.

Another option for me would be to have filebeat call a function in an external library, and that function could add fields to each event.

(ruflin) #9

Agree this should be configurable.

Interesting point from @steffens about the log case. But I assume that is also an issue we face with the other add_* processors?

(system) #10

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.