# How to add IP address to Stream using lookup table

**URL:** <https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111>\
**Category:** Graylog Central (peer support)\
**Created:** [October 11, 2022, 6:27pm UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111 "2022-10-11T18:27:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![aali94](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aali94](https://community.graylog.org/u/aali94)\
**Post date:** [October 11, 2022, 6:27pm UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111/1 "2022-10-11T18:27:57Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

\*\*1. Hello Everyone,

Just wanted to check how can we add assets IP (Address) to Graylog Stream?

There are basically two of of adding IP address to a Stream

```
1. Stream Rule Based (Stream --> Manage Rule -->Add Stream Rule (field: gl2_remote_ip (enter_IP_which_you_want_to_add_to_stream))) --> Save
2. Lookup table based -- Can anyone share what is the method of adding IP address to a Stream using lookup table.

```

Thanks,

Ifty.:\*\*

**2. : We have 4 GL HA, 10 ES HA, & 3 Mongo in Replica Set**

- OS Information: RHEL 7

- Package Version: Graylog 4.0.15

- Service logs, configurations, and environment variables:

**3. What steps have you already taken to try and solve the problem?**

**4. How can the community help?**

**Helpful Posting Tips:** [Tips for Posting Questions that Get Answers](https://community.graylog.org/t/tips-for-posting-questions-that-get-answers/21828) [Hold down CTRL and link on link to open tips documents in a separate tab]

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [October 11, 2022, 9:05pm UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111/2 "2022-10-11T21:05:26Z")

</div>

Are you looking for the DNS lookup table? More info in [docs here](https://docs.graylog.org/docs/lookuptables)…

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 11, 2022, 9:37pm UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111/3 "2022-10-11T21:37:59Z")

</div>

Hello @aali94

Adding on, but I’m not sure what you want to do.  
Here is a example.  
Adding Stream rule with IP Address.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/5c6530916d680b25ff1bb7aa90d7003dda7278e2.png)

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/e9743d7b70a5088120126054ac16dcf2fca899d2.png)

As for a lookup table I have used it on my Input/s. I haven’t use the DNS Lookup as @tmacgbay stated above.

Or you can use “source field” with FQDN

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/8f97c599903e419a21bf407e0b200ddf9b240877.png)

---

<div class="post-metadata">

**Author:** ![aali94](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aali94](https://community.graylog.org/u/aali94)\
**Post date:** [October 12, 2022, 11:39am UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111/4 "2022-10-12T11:39:15Z")

</div>

@tmacgbay :

I am looking to to setup DNS lookup table.

I have created the lookup table following the instructions, the link which you shared (Data Adaptor, Cache, Lookup table).

I think next step is

Cluster Global API → System/Lookup : Lookup tables → Show → GET

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/6d61e31102e2ee516a1fd2b0865a54be565cbaaa.png)

But I am not sure how this adaptor is getting mapped with Stream ID.

Thanks!

---

<div class="post-metadata">

**Author:** ![aali94](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aali94](https://community.graylog.org/u/aali94)\
**Post date:** [October 12, 2022, 11:41am UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111/5 "2022-10-12T11:41:41Z")

</div>

This method of adding IP address to Stream puts more load on the system, therefore Graylog recommends to follow Data Adaptor based addition.

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [October 12, 2022, 1:22pm UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111/6 "2022-10-12T13:22:21Z")

</div>

Can you be more descriptive of what you want? How are you figuring out what IP to put into the message fields? Do you want to translate the `source` field to a separate `source_IP` field based on the DNS table?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 26, 2022, 1:22pm UTC](https://community.graylog.org/t/how-to-add-ip-address-to-stream-using-lookup-table/26111/7 "2022-10-26T13:22:55Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
