# External IPs - Kibana Dashboard - Version 7.9.1

**URL:** <https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337>\
**Category:** Kibana\
**Created:** [November 13, 2020, 12:06pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337 "2020-11-13T12:06:56Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 13, 2020, 12:06pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/1 "2020-11-13T12:06:56Z")

</div>

Good Morning.

I have a problem with Kibana. I need my Kibana to be able to bring the external IPs, it can only show internal IPs on my dashboards. A friend said that I have to log the External IP into my index for this to work, but I don't know how to proceed. My Stack is a 7.9.1 version.

**I'm using Filebeat**

Can anybody help me. Thanks.

This is my first post here.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 13, 2020, 1:35pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/2 "2020-11-13T13:35:27Z")

</div>

If I'm understanding correctly, you want to display external IP but you're not currently storing it. I think the first step is to make sure its being logged. If its logged then its just a matter of configuring filebeat to extract it.

What process are you logging?

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 13, 2020, 3:38pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/3 "2020-11-13T15:38:02Z")

</div>

The IPs of customers who access the web application are being recorded in the **Haproxy log**. I want that Kibana to be able to include them in the application dashboard.

In **Discover/Kibana** the **External IPs appear normally** , but in the Dashboard only Internal IPs appear.

Here my Haproxy Log format:

```auto
Nov 13 12:17:37 SRV haproxy[5101]: **200.200.200.201** ( **External IP Example logged in haproxy** ):37926 [13/Nov/2020:13:17:36.976] http websrvs/srv1 72/0/1/228/301 200 632 - - --NI 250/250/0/1/0 0/0 "POST /sal/WS-Agends HTTP/1.1"

```

Here my Discover Log in Kibana (Getting External IPs from Haproxy path configured in filebeat.yml:

```auto
Nov 13, 2020 @ 12:30:43.089 @timestamp:
Nov 13, 2020 @ 12:30:43.089
message:
**177.177.177.99**.. ( **External IP Example** ) - - [13/Nov/2020:09:31:30 -0300] "POST /site/test/infocall/validdata.jsp?

```

As you can see, the External IPs appear in the haproxy log and in the kibana's discover, but when I create a dashboard, the kibana only brings me Internal IPs.

What do you think can be done?

Thank you.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 14, 2020, 2:48am UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/4 "2020-11-14T02:48:58Z")

</div>

@krinfra

Thats good, it likely means we just need to configure the dashboard visualization to show the correct data. Could you show me a screenshot and perhaps the config of the visualization you'd like to alter?

Thanks,  
Matt

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 16, 2020, 1:31pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/5 "2020-11-16T13:31:00Z")

</div>

![Captura de Tela 2020-11-16 às 10.29.38](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b237dc42d14b903555da226ed7708aa3c330ce4d.png) [quote="mattkime, post:4, topic:255337"]  
ould you show me a screenshot and perhaps the config of the visualization you'd  
[/quote]

 ![Captura de Tela 2020-11-16 às 10.28.45](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6a8918ce9493541d0a8a68b7df2fcfe83fb993bb.png)

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 16, 2020, 3:13pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/6 "2020-11-16T15:13:23Z")

</div>

@krinfra In the top visualization, I see Field set to 'source.ip' - have you considered changing that to your external ip?

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 16, 2020, 3:37pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/7 "2020-11-16T15:37:02Z")

</div>

I try to setup up different options, but without success. I tested with the options that appear with the IP tag. Do I need setup the numeric IP?

I am totally confused. Do I need to log the external IP into the index? If so, how can I do this? I cannot understand why External IPs do not appear, as they appear in Discover.

 ![Captura de Tela 2020-11-16 às 12.32.41](https://us1.discourse-cdn.com/elastic/original/3X/5/4/54eb8d5f4ffecae9c6dd3394bbe33054af4436df.png)

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 16, 2020, 4:36pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/8 "2020-11-16T16:36:53Z")

</div>

Whats the name of the external ip field?

Do you know which index patter is being used for these visualizations? It should be displayed in the upper left of the dashboard. Once you have that go and look at the index pattern in stack management to verify the field is listed.

Discover can display fields that are in docs but aren't individually stored. That might be what we have here.

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 16, 2020, 5:18pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/9 "2020-11-16T17:18:00Z")

</div>

> [@mattkime](#):
>
> h index patter is being used for these visualization

The default index pattern is Filebeat. But I also use Packetbeat and Metricbeat. For this specific view, I'm using the Packetbeat index pattern. All my indexes use some Beat (filebeat, metricbeat and packetbeat).

The question:

My HaProxy logs are saved in a Log Centralizer. Then I put the log path from the Log Centralizer, in the beat configuration file. About the External IP in some field, I don't know how to proceed. I thought Beat would do that automatically.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 16, 2020, 10:54pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/10 "2020-11-16T22:54:54Z")

</div>

> I thought Beat would do that automatically.

I think your expectations are good but we should still double check that things are in the correct state. Can you look at the field list for the respective index pattern in index pattern management?

You can also go to 'Index Management' inside stack management, find an appropriate index and look at its `Mappings` - you should find the field you're looking for listed there. If so, please share its entry.

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 16, 2020, 11:17pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/12 "2020-11-16T23:17:16Z")

</div>

Mappings settings - Filebeat 7.9.1

[https://pastiebin.com/5fb3072f0e860](https://pastiebin.com/5fb3072f0e860)

All beats have this configuration.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 16, 2020, 11:36pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/13 "2020-11-16T23:36:48Z")

</div>

Do you see your field listed? I don't want to make an assumption about the exact name of the field you're looking for.

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 17, 2020, 12:59am UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/14 "2020-11-17T00:59:07Z")

</div>

I found Five entries, but I don't know if they are responsible for bringing the external IPs.

```auto

**One:** 
 "forward_ip": {
                "type": "ip"

**Two**"forward_ipv6": {
                "type": "ip"

**Three**"forwardedfor": {
                "ignore_above": 1024,
                "type": "keyword"

**Four**"remote_ip": {
                "type": "ip"

**Five**"forward_ip": {
                "type": "ip"

```

A friend told me that if the external IP appears in the log, then I just had to include it in a specific field in the kibana. My stack works fine for me. I can create any dashboard according to my intention. However, viewing the External IP captured by Haproxy, it's been a headache.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 17, 2020, 3:07am UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/15 "2020-11-17T03:07:40Z")

</div>

Previously you said that external ips display normally in discover. Can you provide a screenshot of that? It should show the field name.

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 18, 2020, 4:00pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/18 "2020-11-18T16:00:57Z")

</div>

> [@krinfra](#):
>
> Here my Discover Search. I'm using Filebeat. The field that External IPs appears is the **Message Field**. Thank you for your patience.

 ![External_IP_MESSAGE-Field](https://us1.discourse-cdn.com/elastic/original/3X/1/1/11ef7fc519b89587a3f1e61761ef61b565edf76d.jpeg)

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 18, 2020, 4:18pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/19 "2020-11-18T16:18:49Z")

</div>

It looks to me like the message field has the whole log line and therefore isn't useful for a number of use cases. Is there a field that only has the external ip address?

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 18, 2020, 4:37pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/20 "2020-11-18T16:37:06Z")

</div>

Only this field:

```auto
**message:**
    **190.103.111.11** - - [18/Nov/2020:13:33:43 -0300] "GET / HTTP/1.1" 301 162 "http://site.example.com/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36" 

```

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 18, 2020, 4:39pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/21 "2020-11-18T16:39:57Z")

</div>

You should modify your filebeat config to extract the external ip into its own field.

---

<div class="post-metadata">

**Author:** ![krinfra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krinfra/32/76054_2.png) [@krinfra](https://discuss.elastic.co/u/krinfra)\
**Post date:** [November 18, 2020, 4:45pm UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/22 "2020-11-18T16:45:25Z")

</div>

Where in filebeat.yml can I make this change, do you know? I already looked for it, but I couldn't make this change. 😔

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 19, 2020, 4:19am UTC](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337/23 "2020-11-19T04:19:09Z")

</div>

are you using the haproxy module for filebeat? [https://www.elastic.co/guide/en/beats/filebeat/6.8/filebeat-module-haproxy.html](https://www.elastic.co/guide/en/beats/filebeat/6.8/filebeat-module-haproxy.html)

[Next page](https://discuss.elastic.co/t/external-ips-kibana-dashboard-version-7-9-1/255337.md?page=2)
