# IP reputation ELK integration

**URL:** <https://discuss.elastic.co/t/ip-reputation-elk-integration/265959>\
**Category:** Logstash\
**Created:** [March 2, 2021, 1:13pm UTC](https://discuss.elastic.co/t/ip-reputation-elk-integration/265959 "2021-03-02T13:13:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tarekilani](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Post date:** [March 2, 2021, 1:13pm UTC](https://discuss.elastic.co/t/ip-reputation-elk-integration/265959/1 "2021-03-02T13:13:41Z")

</div>

Hello,

Please i'm trying to integrate abuseipdb API to elasticsearch so i can have a reputation score of the IP adressess. When i searched on the internet i only found tutorials talking about integrating abuseipdb with ELK using Logstash. Is there any other way to do it without using Logstash? (Like the Addon of abuseipdb in Splunk SIEM) Or is there any other ip reputation api that i can use?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [March 2, 2021, 2:24pm UTC](https://discuss.elastic.co/t/ip-reputation-elk-integration/265959/2 "2021-03-02T14:24:47Z")

</div>

The only way is to get data enriched before ingesting to elasticsearch  
So Yes Logstash or anyother third party tool that can enrich before ingesting  
That should be easy task with logatsh and Http filter

> **[Using LogStash to add AbuseIPDB confidence scores to IP Addressess](https://securitynotsupported.com/logstash-adding-abuseipdb/)**
>
> Use Logstash pieplines to add metadata, such as AnuseIPDB confidence scores to IP addresses to enrich honeypot logs

---

<div class="post-metadata">

**Author:** ![jfs1](https://avatars.discourse-cdn.com/v4/letter/j/439d5e/32.png) [@jfs1](https://discuss.elastic.co/u/jfs1)\
**Post date:** [March 15, 2021, 11:57am UTC](https://discuss.elastic.co/t/ip-reputation-elk-integration/265959/3 "2021-03-15T11:57:21Z")

</div>

It's theorically possible to update records stored in Elasticsearch, but it requires some custom programming using the raw API. The ELK stack is not designed to use this feature. In a nutshell, logstash ingests/enrich/transforms and kibana displays.

I would not advise using an IP reputation API in your log ingestion pipeline, as you are way too dependant on the reliability of the API provider and you take the risk of losing logging information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2021, 11:58am UTC](https://discuss.elastic.co/t/ip-reputation-elk-integration/265959/4 "2021-04-12T11:58:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
