# X-forwarded-for in audit logs

**URL:** https://discuss.elastic.co/t/x-forwarded-for-in-audit-logs/112531
**Category:** Elasticsearch
**Created:** [December 20, 2017, 12:52am UTC](https://discuss.elastic.co/t/x-forwarded-for-in-audit-logs/112531 "2017-12-20T00:52:26Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [December 20, 2017, 12:52am UTC](https://discuss.elastic.co/t/x-forwarded-for-in-audit-logs/112531/1 "2017-12-20T00:52:26Z")

</div>

Does anyone have a good method for getting the client IP in the security index when you pass through a load balancer? I'm set up in AWS and I can see tons of anonymous\_access\_denied errors but they have the src address all from the ELB. Now I know there's probably some agent out there that's set up incorrectly, but I have no way to track this down. I'm not even getting a non 200 response in the ELB logs, so it's kind of like throwing darts in the dark.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 17, 2018, 12:52am UTC](https://discuss.elastic.co/t/x-forwarded-for-in-audit-logs/112531/2 "2018-01-17T00:52:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
