# Not able to see the source ip field in the auth.log on kibana dashboard

**URL:** <https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577>\
**Category:** Logstash\
**Created:** [January 24, 2017, 7:38am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577 "2017-01-24T07:38:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![shubhrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhrant/32/20310_2.png) [@shubhrant](https://discuss.elastic.co/u/shubhrant)\
**Post date:** [January 24, 2017, 7:38am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/1 "2017-01-24T07:38:59Z")

</div>

hello,

I just want to add the source ip field in the auth.log separate as my auth.log dashboard are showing these field and the source ip flied is showing in the message

 ![](https://us1.discourse-cdn.com/elastic/original/2X/9/98cc2f2403490725fd3691e5d961d0a13e65e975.png)

I want it like this, showing in the below screen sort

![](https://us1.discourse-cdn.com/elastic/original/2X/5/5b0d70a9273528800f3f6180027cf63bc7b0f9ba.png)

my logstash configuration file is

input {  
beats {  
port =\> 5044  
}  
}  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{IP:source\_ip} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
if [type] == "apache" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
geoip {  
source =\> "clientip"  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 24, 2017, 7:59am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/2 "2017-01-24T07:59:46Z")

</div>

You'll have to add a grok filter that extracts the IP address from the `syslog_message` field.

Note that your existing grok filter doesn't work; your event has a `_grokparsefailure` and the filter clearly hasn't extracted the fields. Fix that first.

---

<div class="post-metadata">

**Author:** ![shubhrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhrant/32/20310_2.png) [@shubhrant](https://discuss.elastic.co/u/shubhrant)\
**Post date:** [January 24, 2017, 8:27am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/3 "2017-01-24T08:27:18Z")

</div>

hey magnus good to see you again ,

Can you please tell me what would be the grok filter for extract the IP address from the syslog message field....??

I simply use this grok filter -

if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslo$  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 24, 2017, 9:01am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/4 "2017-01-24T09:01:44Z")

</div>

Yes, but I suggested adding another grok filter that parses the `syslog_message` field. Extracting the IP address from this particular message is way easier than your current expression.

---

<div class="post-metadata">

**Author:** ![shubhrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhrant/32/20310_2.png) [@shubhrant](https://discuss.elastic.co/u/shubhrant)\
**Post date:** [January 24, 2017, 9:08am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/5 "2017-01-24T09:08:22Z")

</div>

ok then what is that another filter.. tell me so that I can add it

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 24, 2017, 9:14am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/6 "2017-01-24T09:14:48Z")

</div>

I don't have time to give everyone detailed and specific help. Please try for yourself and come back if you have any specific questions.

---

<div class="post-metadata">

**Author:** ![shubhrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhrant/32/20310_2.png) [@shubhrant](https://discuss.elastic.co/u/shubhrant)\
**Post date:** [January 24, 2017, 9:15am UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/7 "2017-01-24T09:15:13Z")

</div>

ok thanks

---

<div class="post-metadata">

**Author:** ![shubhrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhrant/32/20310_2.png) [@shubhrant](https://discuss.elastic.co/u/shubhrant)\
**Post date:** [January 24, 2017, 12:29pm UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/8 "2017-01-24T12:29:18Z")

</div>

Thanks magnus I found the grok filter

"%{SYSLOGTIMESTAMP:timestamp} %{HOSTNAME:host\_target} sshd[%{BASE10NUM}]: Accepted password for %{USERNAME:username} from %{IP:src\_ip} port %{BASE10NUM:port} ssh2"

thanks for helping me 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2017, 12:29pm UTC](https://discuss.elastic.co/t/not-able-to-see-the-source-ip-field-in-the-auth-log-on-kibana-dashboard/72577/9 "2017-02-21T12:29:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
