# How to print out %{host.ip} using line codec?

**URL:** <https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750>\
**Category:** Logstash\
**Created:** [April 9, 2021, 9:21pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750 "2021-04-09T21:21:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hmiti](https://avatars.discourse-cdn.com/v4/letter/h/b2d939/32.png) [@hmiti](https://discuss.elastic.co/u/hmiti)\
**Post date:** [April 9, 2021, 9:21pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/1 "2021-04-09T21:21:54Z")

</div>

I am using the line codec to output the logs into a text file. Requested to include only the IP and log entry itself.

Tried different combination of %{host}.{ip} like this, nothing works so far.

```auto
output {
  file {
    path => "/tmp/file_line.txt"
    codec => line { format => "%{host.ip} %{message}" }
  }
}

```

%{host} works, output like:  
2021-04-09T20:47:34.743Z {"name":"hostname","ip":["192.168.0.x"]} log msg  
ideal output like:  
2021-04-09T20:47:34.743Z 192.168.0.x log msg

Any document on how to format?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2021, 10:25pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/2 "2021-04-09T22:25:06Z")

</div>

If you change that to

```
 codec => rubydebug

```

What does the host.ip field look like?

---

<div class="post-metadata">

**Author:** ![hmiti](https://avatars.discourse-cdn.com/v4/letter/h/b2d939/32.png) [@hmiti](https://discuss.elastic.co/u/hmiti)\
**Post date:** [April 9, 2021, 10:36pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/4 "2021-04-09T22:36:14Z")

</div>

```auto
{
          "tags" => [
        [0] "beats_input_codec_plain_applied"
    ],
       "message" => "log msg #28",
    "@timestamp" => 2021-04-09T22:34:45.247Z,
          "host" => {
        "name" => "hostname",
          "ip" => [
            [0] "192.168.0.x",
            [1] "2607:fea8:3c40:84:20c:29ff:fe97:6fb9",
            [2] "fe80::20c:29ff:fe97:6fb9"
        ]
    },
        "fields" => {
        "tags" => "Tag_nginx_access"
    },
      "@version" => "1"
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2021, 11:20pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/5 "2021-04-09T23:20:56Z")

</div>

To reference the first entry in the array you would use

```
format => "%{[host][ip][0]} %{message}"
```

---

<div class="post-metadata">

**Author:** ![hmiti](https://avatars.discourse-cdn.com/v4/letter/h/b2d939/32.png) [@hmiti](https://discuss.elastic.co/u/hmiti)\
**Post date:** [April 9, 2021, 11:50pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/6 "2021-04-09T23:50:52Z")

</div>

My man! Thanks.  
One further question regarding the IP. Is there a way to include only IPv4, not IPv6? We are using filebeat as the input. Ideally to have this filter in filebeat.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 10, 2021, 1:32am UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/7 "2021-04-10T01:32:52Z")

</div>

Yes, u can do a script processor and loop through the `host.ip` field and remove any item that has a `:`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2021, 3:09pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/8 "2021-04-10T15:09:32Z")

</div>

You can use grok to pick out members of the array that are IPV4 addresses

```
grok { match => { "[host][ip]" => "%{IPV4:[@metadata][ip]}" } }

```

That will result in an array if there are more than one V4 addresses in the array, to pick out the first you can use

```
if [@metadata][ip][1] { mutate { replace => { "[@metadata][ip]" => "%{[@metadata][ip][0]}" } } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2021, 3:09pm UTC](https://discuss.elastic.co/t/how-to-print-out-host-ip-using-line-codec/269750/9 "2021-05-08T15:09:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
