# Add IP-addresses and MAC-addresses to event

**URL:** <https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 11, 2017, 5:24am UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465 "2017-10-11T05:24:02Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![hypp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hypp/32/22952_2.png) [@hypp](https://discuss.elastic.co/u/hypp)\
**Post date:** [October 11, 2017, 5:24am UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/1 "2017-10-11T05:24:02Z")

</div>

Hi,

I would like to dynamically add all IP-addresses and all MAC-addresses of the sender host to each event sent by filebeat. Is there a way to do that? If not, I would be happy to contribute a new processor, similar to the add\_locale processor, but for this purpose.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 12, 2017, 11:27am UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/2 "2017-10-12T11:27:31Z")

</div>

Hi @hypp

Interesting timing. We recently started a discussing about which additional host information we should add to an event for example through a processor. Can you open a feature request for this on Github and share some details on how you would implement and which field names you would use?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 12, 2017, 1:25pm UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/3 "2017-10-12T13:25:00Z")

</div>

I'm interested to know how this information would be used and why it's needed.

On a related note there was an enhancement to the logstash beats input to add `[@metadata][ip_address]` to all incoming events. So you could use this to add the source IP to events. [https://github.com/logstash-plugins/logstash-input-beats/issues/180](https://github.com/logstash-plugins/logstash-input-beats/issues/180)

---

<div class="post-metadata">

**Author:** ![hypp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hypp/32/22952_2.png) [@hypp](https://discuss.elastic.co/u/hypp)\
**Post date:** [October 15, 2017, 3:06pm UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/4 "2017-10-15T15:06:49Z")

</div>

I opened issue [#5396](https://github.com/elastic/beats/issues/5396) at Github for this. I hope that is what you wanted me to do?

---

<div class="post-metadata">

**Author:** ![hypp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hypp/32/22952_2.png) [@hypp](https://discuss.elastic.co/u/hypp)\
**Post date:** [October 15, 2017, 3:26pm UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/5 "2017-10-15T15:26:39Z")

</div>

It will be used to track IP-address assignment over time for physical and virtual hardware,  
for both statically assigned and dynamically assigned (DHCP) addresses.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 16, 2017, 7:50am UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/6 "2017-10-16T07:50:36Z")

</div>

@hypp Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 16, 2017, 2:46pm UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/7 "2017-10-16T14:46:22Z")

</div>

Do we really need to add these kind of metadata to each single even from filebeat? Sounds more like a task for metricbeat (or another kind of beat) reporting some info on the hosts environment. For filebeat the issue is (on old logs or on back-pressure), the addresses do not necessarily match the time the log line was written.

---

<div class="post-metadata">

**Author:** ![hypp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hypp/32/22952_2.png) [@hypp](https://discuss.elastic.co/u/hypp)\
**Post date:** [October 16, 2017, 8:34pm UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/8 "2017-10-16T20:34:09Z")

</div>

I definitely want it on every event, even though the data might be wrong in rare cases.  
I suggest making it configurable.

Another option for me would be to have filebeat call a function in an external library, and that function could add fields to each event.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 19, 2017, 7:52am UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/9 "2017-10-19T07:52:36Z")

</div>

Agree this should be configurable.

Interesting point from @steffens about the log case. But I assume that is also an issue we face with the other add\_\* processors?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2017, 7:52am UTC](https://discuss.elastic.co/t/add-ip-addresses-and-mac-addresses-to-event/103465/10 "2017-11-16T07:52:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
