I did prepare a logstash.conf that brings for me ip address from host (winlogbeats). but didn't reach my goal ... all my components are latest version. I need help
What version of Winlogbeat? What version of Windows? What is the message you are trying to parse? From what event log and source is this event generated? What is it's event ID number? If you can provide a sample event as produced by Winlogbeat in JSON form this would help us help you as it would answer all these questions.
For event sources that produce structured data grok is unnecessary. For example, event ID 4625 from the Security log produces a field named event_data.IpAddress that contains just the IP and therefore parsing is not needed. Here are more sample events showing how event_data contains the parameters used in the message.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.