# Source.ip not available in the logs received from windows

**URL:** <https://discuss.elastic.co/t/source-ip-not-available-in-the-logs-received-from-windows/374308>\
**Category:** Elastic Agent\
**Created:** [February 10, 2025, 12:38pm UTC](https://discuss.elastic.co/t/source-ip-not-available-in-the-logs-received-from-windows/374308 "2025-02-10T12:38:13Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![mancharagopan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mancharagopan/32/60266_2.png) [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Post date:** [February 10, 2025, 12:38pm UTC](https://discuss.elastic.co/t/source-ip-not-available-in-the-logs-received-from-windows/374308/1 "2025-02-10T12:38:13Z")

</div>

I have integrated Windows computer and receiving logs using elastic agent. For several security rules source.ip field is required for detection. Instead of source.ip the logs are indexed with host.ip.

how do i change it to source.ip?
