# Cache optimization for ip2location filter problem

**URL:** <https://discuss.elastic.co/t/cache-optimization-for-ip2location-filter-problem/130434>\
**Category:** Logstash\
**Created:** [May 3, 2018, 11:00am UTC](https://discuss.elastic.co/t/cache-optimization-for-ip2location-filter-problem/130434 "2018-05-03T11:00:32Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![deyanskiq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deyanskiq/32/30828_2.png) [@deyanskiq](https://discuss.elastic.co/u/deyanskiq)\
**Post date:** [May 3, 2018, 11:00am UTC](https://discuss.elastic.co/t/cache-optimization-for-ip2location-filter-problem/130434/1 "2018-05-03T11:00:32Z")

</div>

Hello, I have implemented cache optimization for ip2location filter ( which is similar to the default geoip filter). When event (a line of log file) is send for the first time everything is ok ( the ip2location fields are shown in Logstash output and kibana) but when the same event is send for the second time ip2location fields disappeared. The strangest thing is that when I am debugging it at the end of the "filter\_matched(event)" logstash method the ip2location fields are there but when the information is passed to logstash output , it suddenly dissappears.  
Do you have any idea where can be the problem? Do you know which method is called after filter\_matched(event) method in order to pass the json (with the parsed information) to logstash output or elasticsearch? Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 11:00am UTC](https://discuss.elastic.co/t/cache-optimization-for-ip2location-filter-problem/130434/2 "2018-05-31T11:00:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
