Hello, We have a single instance of Graylog . Currently the devices that are sending logs to our Graylog server are showing up by their hostname which is fine. But we are in middle of an investigation and need to find or co-relate hostname of a source with an ip-address. How can i find ip-address of the source that’s sending the message ? The source device in question are Windows 7/10 systems. Also, the device under investigation is a new windows system which has not been seen before & that is why we need to track down its ip.
Also is there a way to enable hostname & ip-address both in the messages for all sources ? Windows Event Viewer by default only has a system hostname written in events for it to forward to syslog server.
We have tried nslookup, ping etc but that device is no longer active on our network so we are relying on graylog for this.