# How to fetch IP address of using winlogbeat?

**URL:** <https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 28, 2017, 7:19am UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409 "2017-12-28T07:19:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Jaiswal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_jaiswal/32/39326_2.png) [@Nikhil\_Jaiswal](https://discuss.elastic.co/u/Nikhil_Jaiswal)\
**Post date:** [December 28, 2017, 7:19am UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/1 "2017-12-28T07:19:45Z")

</div>

Hi,

I installed winlogbeat on host but i am only able to see hostname of the device not source ip.  
Is there any configuration changes required to get source ip ?

---

<div class="post-metadata">

**Author:** ![Mazhar](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@Mazhar](https://discuss.elastic.co/u/Mazhar)\
**Post date:** [December 28, 2017, 8:17am UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/2 "2017-12-28T08:17:17Z")

</div>

@Nikhil_Jaiswal - What is the architecture at your end, from WINLOGBEATS the output is to? If you can throw some light.

---

<div class="post-metadata">

**Author:** ![Nikhil\_Jaiswal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_jaiswal/32/39326_2.png) [@Nikhil\_Jaiswal](https://discuss.elastic.co/u/Nikhil_Jaiswal)\
**Post date:** [December 29, 2017, 7:33am UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/3 "2017-12-29T07:33:56Z")

</div>

i am using ELK stack so the architecture is like

Winlogbeat \>\> logstash \>\> elasticsearch \>\> kibana

i am forwarding all the events from windows.

---

<div class="post-metadata">

**Author:** ![Mazhar](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@Mazhar](https://discuss.elastic.co/u/Mazhar)\
**Post date:** [December 29, 2017, 12:06pm UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/4 "2017-12-29T12:06:02Z")

</div>

@Nikhil_Jaiswal - Are you using any filters in logstash configuration files that is preventing the source IP information. I meant gork in logstash configuration file

---

<div class="post-metadata">

**Author:** ![Nikhil\_Jaiswal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_jaiswal/32/39326_2.png) [@Nikhil\_Jaiswal](https://discuss.elastic.co/u/Nikhil_Jaiswal)\
**Post date:** [December 31, 2017, 6:02am UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/5 "2017-12-31T06:02:45Z")

</div>

**this is my mutate part**

remove\_field =\> ["type"]  
remove\_field =\> ["InsertionStrings"]  
}

```
			mutate {
				
				remove_field => ["keywords"]
				remove_field => ["beat"]
				remove_field => ["tags"]
				remove_field => ["user"]					
				remove_field => ["event_data"]	
				remove_field => ["provider_guid"]
				remove_field => ["process_id"]
				remove_field => ["thread_id"]
				 
				#rename => ["syslog_message" , "messages"]				
				
				
				add_field => ["src_hostname" , "%{host}"]
				add_field => ["src_ip", "%{host}"]
				add_field => ["engine_id", "1518"]
				#add_field => ["engine_log_id", "1"]
				rename => ["event_id" , "engine_log_id"]					
				#rename => ["host" , "src_hostname"]
				#rename => ["clienthost" , "client_IP"]
				#add_field => ["hostname","%{winname}"]
				remove_field => ["host"]	
				}
```

---

<div class="post-metadata">

**Author:** ![Mazhar](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@Mazhar](https://discuss.elastic.co/u/Mazhar)\
**Post date:** [January 2, 2018, 8:40am UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/6 "2018-01-02T08:40:44Z")

</div>

can you change the position of the definition for host and IP and check for the result. As I don't see any problems with the configurations.

I have a query - in Logstash have you configured aggregation on the event data received?

//Mazhar

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 2, 2018, 3:37pm UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/7 "2018-01-02T15:37:06Z")

</div>

> [@Nikhil\_Jaiswal](#):
>
> Is there any configuration changes required to get source ip ?

The IP address of the Beat is added to the event by Logstash. The data is written to the `[@metadata][ip_address]` field. If you want this data to be written to Elasticsearch then you need to copy the data out of the `@metadata` namespace and into the main event with a [mutate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html) filter because the [@metadata](https://www.elastic.co/guide/en/logstash/6.1/event-dependent-configuration.html#metadata) is special in that it is not sent to the output.

- [Include Remote IP address in the Event medata by jakelandis · Pull Request #218 · logstash-plugins/logstash-input-beats · GitHub](https://github.com/logstash-plugins/logstash-input-beats/pull/218)

---

<div class="post-metadata">

**Author:** ![Nikhil\_Jaiswal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_jaiswal/32/39326_2.png) [@Nikhil\_Jaiswal](https://discuss.elastic.co/u/Nikhil_Jaiswal)\
**Post date:** [January 4, 2018, 1:07pm UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/8 "2018-01-04T13:07:45Z")

</div>

Thanks @andrewkroh,

Can you please help me in logstash syntax means how to add in mutate, because i am new in elastic .

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 5, 2018, 5:40pm UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/9 "2018-01-05T17:40:19Z")

</div>

Try

```auto
filter {
	mutate {
		copy => {"[@metadata][ip_address]" => "[beat][ip]"}
	}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2018, 5:40pm UTC](https://discuss.elastic.co/t/how-to-fetch-ip-address-of-using-winlogbeat/113409/10 "2018-02-02T17:40:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
