-
Notifications
You must be signed in to change notification settings - Fork 6.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Logstash: Preserve Host IP #241
Comments
Same problem here. Seems to be related with this: moby/moby#15086. |
One suggestion I have is to deploy your service that requires the source IP using docker-compose rather than docker stack deploy. You'd lose the replica and load balancing but you'd get the source IP. |
@Huppys are the log senders running on the same machine as the Logstash container? The source IP is usually preserved for traffic coming on your external network interface, but it's not for traffic coming on the loopback. In short, try this and compare:
|
Hi @trajano - Do you have any more information on how this could be done? I am seeing the same issue running my stack with |
Looks that is root of issue |
I just used the latest build. Trying to get UPD (Netflow) traffic on Port 9995 but host ip is shown as 172.18.0.1 so how do I fix this? |
Add this to docker-compose.yml:
|
@orgads A bit dangerous to include in the default stack, but very useful for users running into this, thanks for sharing! |
Hey,
I'm collecting some inputs via http plugin. I'd like to seperate data by the hosts IP address.
Due to the fact the docker-elk service is creating his network named
dockerelk_elk
using thebridge
driver, any connection is routed through the gateways ofdockerelk_elk
if it's not coming from within this network.When previewing the collected logs within Kibana, the
host
field always contains the gateways IP address because the requests came from the outside ofdockerelk_elk
.Does anyone has an idea how to preserve the IP address the request is coming from?
I found this issue from the docker repo moby/libnetwork#1994 suggesting to use the
host
network driver. So I startedelasticsearch
andkibana
via the docker-compose service. Afterwards I started logstash viaIn fact, from host network this docker container running logstash cannot connect to another network like
dockerelk_elk
. I randocker network connect dockerelk_elk [LOGSTASH_CONTAINER_ID]
just to get an errorSo it seems to me I have to run all three containers on the same network to get this up and running.
Or does anybody else have a suggestion?
Best,
huppys
The text was updated successfully, but these errors were encountered: