Add log source IP to Windows eventlogs

Hi all, running Graylog 4.3.15 on Ubuntu 20.04. receiving Windows eventlogs from WEF/WEC with NxLog. I’d like to show how hjave Graylog add the IP of the log source host to the message for me. so not replace the source which is currently the source DNS name but have it essentially do the DNS resolve to IP and enrich the message. Has anyone done this?

Hey @David_W

You can use a DNS lookup table . just an idea.

