# 'source\_ip\_fieldname' is user customized, please check is has an ECS compatible name

**URL:** <https://discuss.elastic.co/t/source-ip-fieldname-is-user-customized-please-check-is-has-an-ecs-compatible-name/368078>\
**Category:** Logstash\
**Created:** [October 1, 2024, 9:33am UTC](https://discuss.elastic.co/t/source-ip-fieldname-is-user-customized-please-check-is-has-an-ecs-compatible-name/368078 "2024-10-01T09:33:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mahesh\_Kumar\_S](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@Mahesh\_Kumar\_S](https://discuss.elastic.co/u/Mahesh_Kumar_S)\
**Post date:** [October 1, 2024, 9:33am UTC](https://discuss.elastic.co/t/source-ip-fieldname-is-user-customized-please-check-is-has-an-ecs-compatible-name/368078/1 "2024-10-01T09:33:26Z")

</div>

Hello Elastic community,

After migrating to Logstash 8 i have found a new warning message like

`[WARN][logstash.inputs.udp] 'source_ip_fieldname' is user customized, please check is has an ECS compatible name`

```auto

    udp{
        port =>514
        type =>syslog
        source_ip_fieldname =>"[@metadata][ip_address]"
    }

```

How to resolve it? What is the issue here?

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [October 1, 2024, 11:24am UTC](https://discuss.elastic.co/t/source-ip-fieldname-is-user-customized-please-check-is-has-an-ecs-compatible-name/368078/2 "2024-10-01T11:24:07Z")

</div>

Hi @Mahesh_Kumar_S ,

It is likely that the warning refers to not following the ECS naming conventions. The recommendation from Logstash is to use ECS-compliant field names to ensure that your data is well-structured and can be used consistently across various parts of the Elastic Stack (such as Elasticsearch and Kibana).

You can try using ECS conventions, for example: [Source Fields | Elastic Common Schema (ECS) Reference [8.11] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-source.html)

For instance, try using `source.ip` instead of `source_ip_fieldname => "[@metadata][ip_address]"`:

```auto

udp {
    port => 514
    type => syslog
    source_ip_fieldname => "[source][ip]"
}

```
