# Trying to add a field with the ip address of the host

**URL:** <https://discuss.elastic.co/t/trying-to-add-a-field-with-the-ip-address-of-the-host/50061>\
**Category:** Logstash\
**Created:** [May 14, 2016, 10:37pm UTC](https://discuss.elastic.co/t/trying-to-add-a-field-with-the-ip-address-of-the-host/50061 "2016-05-14T22:37:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Harley\_Burton](https://avatars.discourse-cdn.com/v4/letter/h/d78d45/32.png) [@Harley\_Burton](https://discuss.elastic.co/u/Harley_Burton)\
**Post date:** [May 14, 2016, 10:37pm UTC](https://discuss.elastic.co/t/trying-to-add-a-field-with-the-ip-address-of-the-host/50061/1 "2016-05-14T22:37:48Z")

</div>

I'm sure this is in the docs, and/or here somewhere, but the closest I have been able to find was a thread here from Oct. 2015 with a link to a doc with info that doesn't work on the current version.

I want to add a field to all log entries that will contain the IP Address of the host (where the log originated). I'm thinking a mutate at the bottom of my filter block. Something like

```
mutate {
   add_field => { "host_ip" => "%{someVar}" }
}

```

However, I can't seem to find that "someVar" variable.

I thought about setting to debug, and looking at the data coming in to the filter block, but if I did find the IP in some field/variable (eg. %{host}) I couldn't necessarily assume it will always be the IP Address (eg. %{host}).

I would appreciate any help with this specifically, or a point to someplace that lists all the %{data} available in each scope (input, filter, output).

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 15, 2016, 11:27am UTC](https://discuss.elastic.co/t/trying-to-add-a-field-with-the-ip-address-of-the-host/50061/2 "2016-05-15T11:27:04Z")

</div>

The `host` field typically contains the name of the host where the event originated, but that depends on what kinds of inputs you have. If that field is always set to a sane value you can use a dns filter to transform it into an IP address. IIRC the dns filter always modifies fields in place, in which case you'll want to copy the `host` field into e.g. `hostip` and perform a DNS lookup on _that_ field.

> I would appreciate any help with this specifically, or a point to someplace that lists all the %{data} available in each scope (input, filter, output).

The inputs you have configured define which fields that are available to your filters. The tail end of your last filter is connected to each of your outputs (assuming no conditionals that limit which filters and outputs apply to each message).

---

<div class="post-metadata">

**Author:** ![Harley\_Burton](https://avatars.discourse-cdn.com/v4/letter/h/d78d45/32.png) [@Harley\_Burton](https://discuss.elastic.co/u/Harley_Burton)\
**Post date:** [May 16, 2016, 4:22pm UTC](https://discuss.elastic.co/t/trying-to-add-a-field-with-the-ip-address-of-the-host/50061/3 "2016-05-16T16:22:21Z")

</div>

Thank you.

It looks like, using winlogbeat and filebeat, the hostname is sent, and not all of them have a DNS record to do a lookup on.

The solution that I've come up with is to add a tag with the IP at the WinLogBeat/FileBeat side, and then add a tag %{host} in the filter block for syslog inputs. It's not clean, but the result is every record has a tag containing the IP Address of the originating host.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:57am UTC](https://discuss.elastic.co/t/trying-to-add-a-field-with-the-ip-address-of-the-host/50061/4 "2017-07-06T04:57:29Z")

</div>


