# Getting the IP address of the Winlogbeat host from Logstash

**URL:** <https://discuss.elastic.co/t/getting-the-ip-address-of-the-winlogbeat-host-from-logstash/55444>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 13, 2016, 9:25pm UTC](https://discuss.elastic.co/t/getting-the-ip-address-of-the-winlogbeat-host-from-logstash/55444 "2016-07-13T21:25:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aron\_Pedersen](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@Aron\_Pedersen](https://discuss.elastic.co/u/Aron_Pedersen)\
**Post date:** [July 13, 2016, 9:25pm UTC](https://discuss.elastic.co/t/getting-the-ip-address-of-the-winlogbeat-host-from-logstash/55444/1 "2016-07-13T21:25:14Z")

</div>

In the new upcoming Winlogbeat 5.0.0 will it be able to send the computers IP address to logstash, so that in logstash we can add a Geo Location?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 13, 2016, 10:10pm UTC](https://discuss.elastic.co/t/getting-the-ip-address-of-the-winlogbeat-host-from-logstash/55444/2 "2016-07-13T22:10:08Z")

</div>

Your question is a little vague, so I will assuming you are asking "Will Winlogbeat 5.0.0 report raw event data in a structured format?" The answer to that question is yes. For example, if the event is [4624](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4624) which contains a field called `IpAddress`, this will be reported by Winlogbeat as `event_data.IpAddress`. You'll be able to use Logstash to add geoip information to the event. There is a [blog post](https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat) showing how to use Winlogbeat 5.0 + Logstash to visualize remote logon locations.

If you are asking if Winlogbeat will report the IP address for the computer sending the event then the answer is no.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 15, 2016, 3:42am UTC](https://discuss.elastic.co/t/getting-the-ip-address-of-the-winlogbeat-host-from-logstash/55444/3 "2016-07-15T03:42:46Z")

</div>

The hostname will however be included so it should be possible to use Logstash's dns filter to resolve the hostname to an IP address. Obviously, only routable non-RFC1918 IP addresses are useful with the geoip filter.

---

<div class="post-metadata">

**Author:** ![Aron\_Pedersen](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@Aron\_Pedersen](https://discuss.elastic.co/u/Aron_Pedersen)\
**Post date:** [August 2, 2016, 6:16pm UTC](https://discuss.elastic.co/t/getting-the-ip-address-of-the-winlogbeat-host-from-logstash/55444/4 "2016-08-02T18:16:36Z")

</div>

> [@magnusbaeck](#):
>
> hostname will however be included so it should be possible to use Logstash's dns filter to resolve the hostname to an IP address. Obviously, only routable non-RFC1918 IP addresses are usef

Thank you Magnus that was exactly what I was looking for. Sorry for my late reply.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 8, 2016, 2:13pm UTC](https://discuss.elastic.co/t/getting-the-ip-address-of-the-winlogbeat-host-from-logstash/55444/5 "2016-08-08T14:13:06Z")

</div>


