# Auditbeat IP metadata missing

**URL:** <https://discuss.elastic.co/t/auditbeat-ip-metadata-missing/244162>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 7, 2020, 11:22am UTC](https://discuss.elastic.co/t/auditbeat-ip-metadata-missing/244162 "2020-08-07T11:22:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mozam](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@mozam](https://discuss.elastic.co/u/mozam)\
**Post date:** [August 7, 2020, 11:22am UTC](https://discuss.elastic.co/t/auditbeat-ip-metadata-missing/244162/1 "2020-08-07T11:22:18Z")

</div>

Hello,

I'm using the below pipeline to index data to Elasticsearch (Elastic 7.8.0 is used).

**Auditbeat -\> Logstash -\> Elasticsearch**

Using the below mutate filter I'm able to copy the IP address from metadata to a new field called **test.ip** which is working fine.

```auto
	mutate {
		copy => {"[@metadata][ip_address]" => "[test][ip]"}
	}

```

But, when I introduced a Kafka into the pipeline as shown below.

**Auditbeat -\> Kafka -\> Logstash -\> Elasticsearch**

I'm not getting the IP address in **test.ip** field, instead my metadata field contains only below fields.

```auto
"@metadata": {
    "beat": "auditbeat",
    "type": "_doc",
    "version": "7.8.0"
  }

```

The **ip\_address** from metadata field exist only if the pipeline is Auditbeat -\> Logstash ?  
How I can capture the host ip address, since my Auditbeat -\> Elasticsearch pipeline data does not contain my public ip for geo ip informations ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2020, 1:22pm UTC](https://discuss.elastic.co/t/auditbeat-ip-metadata-missing/244162/2 "2020-09-04T13:22:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
