# Filters in logstash for sending the logs to elastic search index

**URL:** <https://discuss.elastic.co/t/filters-in-logstash-for-sending-the-logs-to-elastic-search-index/69343>\
**Category:** Logstash\
**Created:** [December 17, 2016, 1:46pm UTC](https://discuss.elastic.co/t/filters-in-logstash-for-sending-the-logs-to-elastic-search-index/69343 "2016-12-17T13:46:31Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![Makra](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@Makra](https://discuss.elastic.co/u/Makra)\
**Post date:** [December 18, 2016, 7:21pm UTC](https://discuss.elastic.co/t/filters-in-logstash-for-sending-the-logs-to-elastic-search-index/69343/11 "2016-12-18T19:21:33Z")

</div>

Hi  
Troy  
Issue remains when the logstash reads the logs from syslog-ng server . instead of IP address , this value =\> 'Source\_IP:%{[\_source][SOURCEIP]}' is being added added. whereas the the same config from command line ( -f option) added the source IP. The difference is that in the test.conf the input is-  
input {  
stdin { codec =\> json }

}

as described in [Add field from JSON / logstash filter](https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364)  
whereas in the dev. environment the input section is-\>

input {  
tcp {  
port =\> 9999  
type =\> "syslog-all"  
tags =\> ["Syslog-All"]  
codec =\> json  
}  
udp {  
port =\> 9999  
type =\> "syslog-all"  
tags =\> ["Syslog-All"]  
codec =\> json  
}  
}

logs did arrive in the kibana dashboard for the above input but with this =\> Source\_IP:%{[\_source][SOURCEIP]}

Really puzzling

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/cd4bccd13f01a1774c08694b5c0940afd7e77bee.png)

---

_[View the full topic](https://discuss.elastic.co/t/filters-in-logstash-for-sending-the-logs-to-elastic-search-index/69343)._
