# Client ip address

**URL:** https://discuss.elastic.co/t/client-ip-address/71431
**Category:** Elasticsearch
**Created:** [January 12, 2017, 8:34pm UTC](https://discuss.elastic.co/t/client-ip-address/71431 "2017-01-12T20:34:57Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)
#### Post date: [January 12, 2017, 8:34pm UTC](https://discuss.elastic.co/t/client-ip-address/71431/1 "2017-01-12T20:34:57Z")

</div>

Hi  
I saw log coming from my dns and it include client ip address requesting domain names. I want to add that client to my list of field where i can seach for what domain it request etc etc ... how can i add that client ip address as a filed which i don't see in the lost.

---

<div class="post-metadata">

### Author: ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)
#### Post date: [January 15, 2017, 10:57pm UTC](https://discuss.elastic.co/t/client-ip-address/71431/2 "2017-01-15T22:57:37Z")

</div>

anybody in the house ????

---

<div class="post-metadata">

### Author: ![xavierfacq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavierfacq/32/8744_2.png) [@xavierfacq](https://discuss.elastic.co/u/xavierfacq)
#### Post date: [January 16, 2017, 3:07pm UTC](https://discuss.elastic.co/t/client-ip-address/71431/3 "2017-01-16T15:07:17Z")

</div>

Your question is not very clear, so can you explain where is the problem with your Elasticsearch ?  
Please provide : Elasticsearch version, number of nodes, configuration or log files.

---

<div class="post-metadata">

### Author: ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)
#### Post date: [January 16, 2017, 5:22pm UTC](https://discuss.elastic.co/t/client-ip-address/71431/4 "2017-01-16T17:22:22Z")

</div>

Thanks xavier

My document contain bind DNS log pattern like shown below on Kibana

yslog\_pid:  
17195  
syslog\_severity\_code:  
5  
offset:  
2,831,951,196  
syslog\_facility:  
user-level  
input\_type:  
log  
syslog\_facility\_code:  
1  
source:  
/var/log/bind.log  
syslog\_program:  
named  
message:  
Jan 16 09:18:49 ns4 named[17195]: 16-Jan-2017 09:18:49.644 client 202.134.31.158#50378 ([e6858.dsce9.akamaiedge.net](http://e6858.dsce9.akamaiedge.net)): view unga-dmz: query: [e6858.dsce9.akamaiedge.net](http://e6858.dsce9.akamaiedge.net) IN A + (202.134.24.120)  
type:  
syslog  
syslog\_message:  
16-Jan-2017 09:18:49.644 client 202.134.31.158#50378 (e6858.dsce9.akamaiedg?

if you see the highlighted keywork are available fields where i can search etc etc but i want to add client, view, query etc etc to the available fields where i can use that for search and analyzed .... i hpe this makes sense now ... please elt me know if you need more clarification about my question.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 13, 2017, 5:22pm UTC](https://discuss.elastic.co/t/client-ip-address/71431/5 "2017-02-13T17:22:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
