# Can't get geoip to work

**URL:** <https://discuss.elastic.co/t/cant-get-geoip-to-work/160577>\
**Category:** Logstash\
**Created:** [December 12, 2018, 3:54pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577 "2018-12-12T15:54:14Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [December 12, 2018, 3:54pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/1 "2018-12-12T15:54:15Z")

</div>

All,

Despite many, many attempts, I've not been able to make geoip work. I don't see the "clientip" field in any of my indices, nor is geoip an option when trying to create a Coordinate Map | Geo Coordinates Bucket | Aggregation Geohash | Field (geoip.location is available, but geo\_point is grey-out, and the visualization produces no output). I have three conf files (input, filter, output), which I've posted here filter is very long; I've posted only what I believe is the relevant part): [https://pastebin.com/SKVfQmBW](https://pastebin.com/SKVfQmBW) .

This has made me crazy for the longest time, and I hope someone can help get me straightened away (with very detailed instructions, if you'd be kind enough). Please let me know if you require any additional information.

Many thanks.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [December 12, 2018, 4:08pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/2 "2018-12-12T16:08:50Z")

</div>

Oh, and this is from my filebeat.yml:

- type: log

The apache-2 module is enabled.

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 12, 2018, 4:35pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/3 "2018-12-12T16:35:22Z")

</div>

You've got a lot wrong going on here.

1. You're harvesting your apache logs via Filebeat log input
2. Dont use [document\_type](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document_type)
3. Then you said you have the apache2 module enabled (you should not be harvesting the log using both methods)
4. if you dont need the additional event processing power of logstash, the Filebeat [apache2 module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache2.html) and its ingest pipelines should do everything you want.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [December 12, 2018, 4:50pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/4 "2018-12-12T16:50:29Z")

</div>

Thanks for the reply, phil. I'm not surprised that I have a log wrong going on. Hence the fact that it doesn't work.

To fix, do I remove all of the geoip-related stuff in my logstash configs? If not, what specifically do I need to do?

Again, thanks.

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 12, 2018, 5:00pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/5 "2018-12-12T17:00:49Z")

</div>

Not necessary to remove the logstash config just yet. Just follow the documentation that I linked to for the Filebeat Apache2 module to configure it. You'll need to remove the filebeat.yml settings that are harvesting the same logs as the Apache2 module. Then just configure the output to be Elasticsearch instead of Logstash and lets see what you get. Make sure you have the ingest-user-agent and ingest-geoip plugins installed. Docs [here](https://www.elastic.co/guide/en/elasticsearch/plugins/current/installation.html)

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [December 12, 2018, 5:57pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/6 "2018-12-12T17:57:53Z")

</div>

Unfortunately, things now seem to really be going sideways. On one of my linux hosts, I changed filebeat.yml to use elasticsearch, rather than logstash, as follows:

output.elasticsearch:  
# Array of hosts to connect to.  
hosts: ["10.0.101.101:9200"]

# Optional protocol and basic auth credentials.  
protocol: "https"  
username: "elastic"  
password: "mypassword"

But now, I see the following in the filebeat log:

2018-12-12T12:54:27.386-0500 ERROR instance/beat.go:824 Exiting: Error importing Kibana dashboards: fail to create the Elasticsearch loader: Error creating Elasticsearch client: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch [http://10.0.101.101:9200](http://10.0.101.101:9200): Get [http://10.0.101.101:9200](http://10.0.101.101:9200): dial tcp 10.0.101.101:9200: connect: connection timed out]  
Exiting: Error importing Kibana dashboards: fail to create the Elasticsearch loader: Error creating Elasticsearch client: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch [http://10.0.101.101:9200](http://10.0.101.101:9200): Get [http://10.0.101.101:9200](http://10.0.101.101:9200): dial tcp 10.0.101.101:9200: connect: connection timed out]

Then, filebeat dies. Huh?

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 12, 2018, 6:21pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/7 "2018-12-12T18:21:08Z")

</div>

Well, your Logstash config is using http for its Elasticsearch output. I assume you haven't changed this requirement, so your Filebeat.yml file should be using http as well. You have it set to https.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [December 12, 2018, 6:24pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/8 "2018-12-12T18:24:47Z")

</div>

I previously changed it to http, and it still failed. I actually copied the error (above) from when it was set to http.

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 12, 2018, 6:27pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/9 "2018-12-12T18:27:22Z")

</div>

What is the elasticsearch.yml file configured for in the "network" section? In particular the following: network.host, http.port. Any firewall between the two that are blocking communication? Do you have xpack security enabled? if you do, please list the relevant settings, i.e. xpack.security.http.ssl \*

- Also...very bad practice to use the "elastic" user for your Filebeat config. That is a special privileged account that has superuser access. You should follow the Filebeat setup instructions and create a filebeat\_internal user.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [December 12, 2018, 6:31pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/10 "2018-12-12T18:31:47Z")

</div>

elasticsearch.yml:

# ---------------------------------- Network -----------------------------------

# 

# Set the bind address to a specific IP (IPv4 or IPv6):

# 

network.host: 10.0.101.101

# 

# Set a custom port for HTTP:

# 

http.port: 9200

# 

# For more information, consult the network module documentation.

No firewall issues.

x-pack security is not enabled.

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 12, 2018, 6:33pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/11 "2018-12-12T18:33:41Z")

</div>

See my previous comment edits. From the looks of your elasticsearch config, you should be using http and not https. If xpack security is not enabled, then you shouldn't be using basic auth credentials in your Filebeat config.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [December 13, 2018, 1:51pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/12 "2018-12-13T13:51:30Z")

</div>

Not sure now if I should be posting to the filebeat forum, but I think I'm making some progress here, with bigphil's help.

A test node is now set up to input filebeat stuff to elasticsearch, rather than logstash. I've commented out any filebeat.inputs regarding httpd in filebeat.yml (along with an additional small tweak or two). The filebeat apache2 module is enabled on the test host. The ingest-user-agent and ingest-geoip plugins are installed on the elastic cluster. Everything seems to be working fine, with regard to the test node sending logs/elasticsearch receiving the logs/logs showing in Kibana. However, geoip still doesn't seem to work. It doesn't seem like the httpd access\_log information is received, for one thing.

I would still greatly appreciate help. I must be close on this one. Of course, I'll provide any other information you deem important.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2019, 2:04pm UTC](https://discuss.elastic.co/t/cant-get-geoip-to-work/160577/13 "2019-01-10T14:04:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
