# Want Alert when New IP Found, How to do that?

**URL:** <https://discuss.elastic.co/t/want-alert-when-new-ip-found-how-to-do-that/304730>\
**Category:** Elastic Security\
**Tags:** elastic-stack-alerting, ingest-pipeline\
**Created:** [May 14, 2022, 2:29pm UTC](https://discuss.elastic.co/t/want-alert-when-new-ip-found-how-to-do-that/304730 "2022-05-14T14:29:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dhia\_Saibi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhia_saibi/32/102422_2.png) [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Post date:** [May 14, 2022, 2:29pm UTC](https://discuss.elastic.co/t/want-alert-when-new-ip-found-how-to-do-that/304730/1 "2022-05-14T14:29:16Z")

</div>

Hi,  
I've parsed the logs to get new fields and specifically the `client.ip` field using this ingest piepline

```auto
PUT _ingest/pipeline/disscus-ip
{
  "description": "",
  "processors": [
    {
      "grok": {
        "field": "message",
        "patterns": [
          "%{NUMBER:http_status} %{IP:client.ip} %{URIPATH:url_path} %{NUMBER:count} %{NUMBER:last_access} %{USER:user.name}"
        ]
      }
    }
  ]
}

```

now I can find all the new fields : `http_status` , `url_path` ,`count` and `last_access`  
but I don't find the `client.ip` like shown in the picture below:

 ![ezf](https://us1.discourse-cdn.com/elastic/original/3X/1/7/176c7db28ccee6f782f917b25f04196534fd610d.png)

client.ip doesn't match any options

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2022, 2:29pm UTC](https://discuss.elastic.co/t/want-alert-when-new-ip-found-how-to-do-that/304730/2 "2022-06-11T14:29:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
