# Record originating IP of filebeats

**URL:** <https://discuss.elastic.co/t/record-originating-ip-of-filebeats/39151>\
**Category:** Logstash\
**Created:** [January 13, 2016, 6:53pm UTC](https://discuss.elastic.co/t/record-originating-ip-of-filebeats/39151 "2016-01-13T18:53:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tun0](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@tun0](https://discuss.elastic.co/u/tun0)\
**Post date:** [January 13, 2016, 6:53pm UTC](https://discuss.elastic.co/t/record-originating-ip-of-filebeats/39151/1 "2016-01-13T18:53:53Z")

</div>

I currently have a fairly simple setup consisting of running several filebeat instances on various hosts, talking to a central logstash instance, which in turn talks to a ES cluster (6 nodes total, 1 also runs logstash).

Currently I only see the hostname of the hosts running filebeat, but I'd like to see the IP as well. Now I know that the hostname is sent by filebeat itself, and I'd prefer the IP address to be based on what logstash sees. Is this currently possible somehow? Otherwise I'd have to "hardcode" the IP addresses into filebeat configs (using puppet or whatever), but that'd less ideal.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 15, 2016, 7:03am UTC](https://discuss.elastic.co/t/record-originating-ip-of-filebeats/39151/2 "2016-01-15T07:03:07Z")

</div>

Using the [dns filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html) isn't an option?

---

<div class="post-metadata">

**Author:** ![tun0](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@tun0](https://discuss.elastic.co/u/tun0)\
**Post date:** [January 15, 2016, 7:19am UTC](https://discuss.elastic.co/t/record-originating-ip-of-filebeats/39151/3 "2016-01-15T07:19:49Z")

</div>

I don't think so, no. As I don't have any FQDN's in the incoming data. If filebeat would send the FQDN, then that'd be a start. I could add it as a custom field (same for the IP), but I prefer to keep my filebeats' configs as simple and generic as possible.

---

<div class="post-metadata">

**Author:** ![asktomsk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asktomsk/32/7203_2.png) [@asktomsk](https://discuss.elastic.co/u/asktomsk)\
**Post date:** [January 17, 2016, 5:02pm UTC](https://discuss.elastic.co/t/record-originating-ip-of-filebeats/39151/4 "2016-01-17T17:02:37Z")

</div>

This is very important feature for me too. I think it should be very common to have a public IP of log sender (e.g. filebeat) in the index. Embedded "host" variable is actually providing by filebeat and usually contains private host name.  
There are some thoughts here: [http://stackoverflow.com/questions/26971079/getting-ip-address-of-logstash-forwarder-machine](http://stackoverflow.com/questions/26971079/getting-ip-address-of-logstash-forwarder-machine)  
But I can't figure out how to use it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/record-originating-ip-of-filebeats/39151/5 "2017-07-06T05:15:25Z")

</div>


