# Need to map ip address from logs to map with corresponding hostname

**URL:** <https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499>\
**Category:** Kibana\
**Created:** [January 16, 2022, 12:49pm UTC](https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499 "2022-01-16T12:49:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ArchitG358](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/architg358/32/98900_2.png) [@ArchitG358](https://discuss.elastic.co/u/ArchitG358)\
**Post date:** [January 16, 2022, 12:49pm UTC](https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499/1 "2022-01-16T12:49:21Z")

</div>

I have logs that includes IP address I want to map IP address to its hostname (eg, AWS ec2) or its organisation.  
Just like whatsmyipaddress does. Need suggestions or plugins that can help do this.  
I am open to get any of the details - Hostname/ISP/Organisation.

**Or basic reverse DNS Lookup will also work**

eg (public IP)-  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c48a8aac5c46380e76ce69e36dfb8139f314d55.png)

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 16, 2022, 2:11pm UTC](https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499/2 "2022-01-16T14:11:16Z")

</div>

If you are using Logstash, dns filter plugin wil help you.

> **[Dns filter plugin | Logstash Reference \[7.16\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html)**

---

<div class="post-metadata">

**Author:** ![ArchitG358](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/architg358/32/98900_2.png) [@ArchitG358](https://discuss.elastic.co/u/ArchitG358)\
**Post date:** [January 16, 2022, 3:10pm UTC](https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499/3 "2022-01-16T15:10:23Z")

</div>

Thanks for the suggeestion.  
I am currently using kibana elastic.  
does this support plugin?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 17, 2022, 12:18am UTC](https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499/4 "2022-01-17T00:18:30Z")

</div>

How do you load your logs to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 17, 2022, 1:52am UTC](https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499/5 "2022-01-17T01:52:33Z")

</div>

You can Use an Ingest Pipeline for ASN and Organization

> **[Ingest pipelines | Elasticsearch Guide \[7.16\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html)**

With GeoIP Processor

> **[GeoIP processor | Elasticsearch Guide \[7.16\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/geoip-processor.html)**

And configure for ISP / ASN options

```auto
PUT _ingest/pipeline/discuss-geoip
{
  "processors": [
    {
      "geoip": {
        "ignore_missing": true,
        "database_file": "GeoLite2-ASN.mmdb",
        "field": "ip",
        "target_field": "as",
        "properties": [
          "asn",
          "organization_name"
        ]
      }
    }
  ]
}

```

```auto
POST discuss-index/_doc?pipeline=discuss-geoip
{
  "ip": "8.8.8.8"
}

```

```auto
GET discuss-index/_search

```

results

```auto
{
  "took" : 104,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 1,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "discuss-index",
        "_id" : "ECjEZX4BE6hlKdvwv5MT",
        "_score" : 1.0,
        "_source" : {
          "as" : {
            "organization_name" : "GOOGLE",
            "asn" : 15169
          },
          "ip" : "8.8.8.8"
        }
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2022, 1:52am UTC](https://discuss.elastic.co/t/need-to-map-ip-address-from-logs-to-map-with-corresponding-hostname/294499/6 "2022-02-14T01:52:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
