# Can we create two GeoIP Filters in one logstash config file?

**URL:** <https://discuss.elastic.co/t/can-we-create-two-geoip-filters-in-one-logstash-config-file/42849>\
**Category:** Logstash\
**Created:** [February 26, 2016, 12:55pm UTC](https://discuss.elastic.co/t/can-we-create-two-geoip-filters-in-one-logstash-config-file/42849 "2016-02-26T12:55:09Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [July 15, 2016, 7:57am UTC](https://discuss.elastic.co/t/can-we-create-two-geoip-filters-in-one-logstash-config-file/42849/11 "2016-07-15T07:57:53Z")

</div>

Hi Cody,

This is what you need to do . Assuming you are using ES1.7.X, because things are slight different if you are on ES2.X

step 1 --\> In LS you need to update target for src\_geoip and dst\_geoip as geoip , something like (be sure src and dst fields should be IP type)

geoip { source =\> "src" target =\> "srcgeoip" }  
geoip {source =\> "dst" target =\> "dstgeoip" }

Step 2) In ES template or using API you need to map fields to Geo\_point

"srcgeoip" : {"type" : "object","dynamic": true,"path": "full","properties" : {"location" : { "type" : "geo\_point" }}},  
"dstgeoip" : {"type" : "object","dynamic": true,"path": "full","properties" : {"location" : { "type" : "geo\_point" }}}

Step 3) now parse your data and you will see something like this in Kibana4.1.1  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a25654259b84c7438bfd191703df79f1893a5355.png)

Let me know if you have more queries or concern on this

Thanks  
VG

---

_[View the full topic](https://discuss.elastic.co/t/can-we-create-two-geoip-filters-in-one-logstash-config-file/42849)._
