# Suricata module - no parsing for XFF field (x forward ip)

**URL:** <https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 14, 2020, 8:07pm UTC](https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641 "2020-12-14T20:07:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sportelh](https://avatars.discourse-cdn.com/v4/letter/s/e9bcb4/32.png) [@sportelh](https://discuss.elastic.co/u/sportelh)\
**Post date:** [December 14, 2020, 8:07pm UTC](https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641/1 "2020-12-14T20:07:37Z")

</div>

Hi Guys,

I am playing arround with ELK for suricata logs, to see if it is suitable for my employer  
I have created some nice dashboards (kibana) so far so good.

But to my surprise there is no suricata.eve field for the "xff" info in the suricata eve.json file!  
For http traffic that's the real ip if you are behind a reverse proxy or so. This is an old option in the suricata config.

How can i add this extra field?

see also the list of exported fields for the suricata modiule, there is no mention of xff data

> **[Suricata fields | Filebeat Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-suricata.html)**

snippet from the eve.json log file:

en","http\_user\_agent":"Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36"," **xff**":"172.25.232.35","http\_content\_type":"text/html","http\_refer":"htt

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [December 15, 2020, 8:26am UTC](https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641/2 "2020-12-15T08:26:55Z")

</div>

It looks like a miss. Would you mind opening an issue for Beats, so the team can look and prioritize it?

---

<div class="post-metadata">

**Author:** ![sportelh](https://avatars.discourse-cdn.com/v4/letter/s/e9bcb4/32.png) [@sportelh](https://discuss.elastic.co/u/sportelh)\
**Post date:** [December 15, 2020, 11:23am UTC](https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641/3 "2020-12-15T11:23:28Z")

</div>

Hi Marcin,

Thnx for the reply, i am not sure how to open an issue for beats?  
how can i do that?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [December 15, 2020, 12:40pm UTC](https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641/4 "2020-12-15T12:40:09Z")

</div>

Please navigate to this page, select issue type and write a report: [https://github.com/elastic/beats/issues/new/choose](https://github.com/elastic/beats/issues/new/choose)

---

<div class="post-metadata">

**Author:** ![sportelh](https://avatars.discourse-cdn.com/v4/letter/s/e9bcb4/32.png) [@sportelh](https://discuss.elastic.co/u/sportelh)\
**Post date:** [December 15, 2020, 6:02pm UTC](https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641/5 "2020-12-15T18:02:07Z")

</div>

I issued an enhancement request, ticket nr. #23149

thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2021, 8:02pm UTC](https://discuss.elastic.co/t/suricata-module-no-parsing-for-xff-field-x-forward-ip/258641/6 "2021-01-12T20:02:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
