# How to add hostname to logs from syslog or snmp source if they don't include only IP, no hostname

**URL:** <https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691>\
**Category:** Logstash\
**Created:** [June 10, 2023, 1:53pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691 "2023-06-10T13:53:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PackElend](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/packelend/32/39268_2.png) [@PackElend](https://discuss.elastic.co/u/PackElend)\
**Post date:** [June 10, 2023, 1:53pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691/1 "2023-06-10T13:53:37Z")

</div>

Hello,  
I'm aware of [How to add hostname to logs that normally do not contain hostname?](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-that-normally-do-not-contain-hostname/54173) but that is not applicable to my case.  
My router's firewall sends syslog message but they only contain the IP of the host causing the rule being triggered.  
I could provide IP\<\>hostname mapping by different means to ELKI.  
How to manipulate the log message on ELKI, so that it contains the IP owner's hostname?

Thank you  
Stefan

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 10, 2023, 2:29pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691/2 "2023-06-10T14:29:44Z")

</div>

> [@PackElend](#):
>
> I could provide IP\<\>hostname mapping by different means to ELKI.  
> How to manipulate the log message on ELKI, so that it contains the IP owner's hostname?

If you have the host name associated to each IP address you could use a translate filter in Logstash to enrich your document while processing.

Check the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#_description_158) for the translate filter.

I also have this [example](https://web.leandrojmp.com/posts/en/2021/02/logstash-translate) that I wrote a time ago on how to set up the translate filter using a dictionary file.

---

<div class="post-metadata">

**Author:** ![PackElend](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/packelend/32/39268_2.png) [@PackElend](https://discuss.elastic.co/u/PackElend)\
**Post date:** [June 10, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691/3 "2023-06-10T14:54:40Z")

</div>

Thx for the quick response.  
great knowing that there is an option.  
I found a script in the MikroTik forum, sharing DHCP clients hostnames using SNMP.  
Need to figure out how to combine these things but reads feasible

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2023, 2:55pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691/4 "2023-07-08T14:55:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
