# Getting external IP from gke node

**URL:** <https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 2, 2020, 5:34pm UTC](https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832 "2020-10-02T17:34:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roman\_Kournjaev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roman_kournjaev/32/2552_2.png) [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Post date:** [October 2, 2020, 5:34pm UTC](https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832/1 "2020-10-02T17:34:40Z")

</div>

Hi  
I am running beats on GKE and wondering whether its possible to get the external IP of the node that i am running on with the

```auto
processors:
   - add_host_metadata:

```

what i am getting now is the internal google ip which is really not much of an interest for me

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79b380a2e2af05bfee68edd23e0e94c7cef93943.png)

I have a lot of clusters spread around the world and wanted to use geoip to map them on an interactive kibana map  
I have been googling for a couple of hours already , but dont see to see anyone who asked about that somewhere.

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [October 5, 2020, 10:28pm UTC](https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832/2 "2020-10-05T22:28:01Z")

</div>

Hi! I haven't tried this myself but maybe other processors will give the IP information you need?! For example [add\_kubernetes\_metadata](https://www.elastic.co/guide/en/beats/metricbeat/current/add-kubernetes-metadata.html) or [add\_cloud\_metadata](https://www.elastic.co/guide/en/beats/metricbeat/current/add-cloud-metadata.html).

---

<div class="post-metadata">

**Author:** ![Roman\_Kournjaev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roman_kournjaev/32/2552_2.png) [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Post date:** [October 6, 2020, 3:47am UTC](https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832/3 "2020-10-06T03:47:06Z")

</div>

I am just going to put that here in case someone needs it.  
I am basically maintaining my own Filebeat image now.

Dockerfile

```auto
ARG ES_VERSION
FROM docker.elastic.co/beats/filebeat:${ES_VERSION}
COPY entrypoint-override.sh /usr/local/bin/docker-entrypoint-override
USER root
RUN chmod u+x /usr/local/bin/docker-entrypoint-override
USER filebeat
ENTRYPOINT ["/usr/local/bin/docker-entrypoint-override"]

```

entrypoint-override.sh

```auto
#!/bin/sh

external_ip=$(curl --silent -H "Metadata-Flavor: Google" http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/0/access-configs/0/external-ip)

if ["$external_ip" != "Not Found"]; then
  export EXTERNAL_IP="$external_ip"
  echo "setting external IP to $external_ip"
fi;

exec "/usr/local/bin/docker-entrypoint" "$@"

```

Then you can use a simple `add_field` processor

```auto
      - add_fields:
          target: host
          fields:
            external_ip: ${EXTERNAL_IP:not_found}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2020, 5:47am UTC](https://discuss.elastic.co/t/getting-external-ip-from-gke-node/250832/4 "2020-11-03T05:47:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
