# Configure ingest pipeline to add both GeoLite2-City AND GeoLite2-ASN fields

**URL:** <https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [January 3, 2024, 7:37pm UTC](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339 "2024-01-03T19:37:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jbrowe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrowe/32/99821_2.png) [@jbrowe](https://discuss.elastic.co/u/jbrowe)\
**Post date:** [January 3, 2024, 7:37pm UTC](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339/1 "2024-01-03T19:37:42Z")

</div>

I have and event stream that contains IP addresses. I wish to add meta-data from the GeoLite2 Max Mind databases. I can successfully add the city data. I can also successfully add the ASN data. Somehow, I cannot add both. If I include two geoip processors sequentially, only the last processor is used. More specifically...

My document:

```auto
[
  {
    "_id": "uiqk0IwBfixXPP18xyzX",
    "_index": ".event-stream-2024.01.01-000161",
    "_source": {
      "source": {
        "ip": "98.41.133.131"
      }
    }
  }
]

```

The first ingest pipeline configuration with the default city database listed last only gives the city data. Evidently it overwrites the ASN result.

```auto
{
  "version": 1,
  "description": "Pipeline to create consistent geo location data from source.ip.",
  "processors": [
    {
      "geoip": {
        "field": "source.ip",
        "target_field": "source.geo",
        "database_file": "GeoLite2-ASN.mmdb",
        "first_only": false
      }
    },
    {
      "geoip": {
        "field": "source.ip",
        "target_field": "source.geo",
        "first_only": false
      }
    },
    {
      "set": {
        "field": "dev",
        "value": "success"
      }
    }
  ],
  "on_failure": [
    {
      "set": {
        "field": "dev",
        "value": "failed"
      }
    }
  ]
}

```

The first result...

```auto
{
  "docs": [
    {
      "doc": {
        "_index": ".event-stream-2024.01.01-000161",
        "_id": "uiqk0IwBfixXPP18xyzX",
        "_version": "-3",
        "_source": {
          "dev": "success",
          "source": {
            "geo": {
              "continent_name": "North America",
              "region_iso_code": "US-CA",
              "city_name": "Sacramento",
              "country_iso_code": "US",
              "country_name": "United States",
              "region_name": "California",
              "location": {
                "lon": -121.5114,
                "lat": 38.6415
              }
            },
            "ip": "98.41.133.131"
          }
        },
        "_ingest": {
          "timestamp": "2024-01-03T19:30:51.015897141Z"
        }
      }
    }
  ]
}

```

Second ingest pipeline configuration with ASN coming last produces the opposite result.

```auto
{
  "version": 1,
  "description": "Pipeline to create consistent geo location data from source.ip.",
  "processors": [
    {
      "geoip": {
        "field": "source.ip",
        "target_field": "source.geo",
        "first_only": false
      }
    },
    {
      "geoip": {
        "field": "source.ip",
        "target_field": "source.geo",
        "database_file": "GeoLite2-ASN.mmdb",
        "first_only": false
      }
    },
    {
      "set": {
        "field": "dev",
        "value": "success"
      }
    }
  ],
  "on_failure": [
    {
      "set": {
        "field": "dev",
        "value": "failed"
      }
    }
  ]
}

```

The second result...

```auto
{
  "docs": [
    {
      "doc": {
        "_index": ".event-stream-2024.01.01-000161",
        "_id": "uiqk0IwBfixXPP18xyzX",
        "_version": "-3",
        "_source": {
          "dev": "success",
          "source": {
            "geo": {
              "ip": "98.41.133.131",
              "organization_name": "COMCAST-7922",
              "asn": 7922,
              "network": "98.40.0.0/14"
            },
            "ip": "98.41.133.131"
          }
        },
        "_ingest": {
          "timestamp": "2024-01-03T19:35:00.865475631Z"
        }
      }
    }
  ]
}

```

How can I get both added to the event?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 4, 2024, 12:00am UTC](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339/2 "2024-01-04T00:00:58Z")

</div>

Hi @jbrowe I suspect it is because the 2nd geoip is completely overwriting the target fields... Try 2 different target fields then you may need to self combine/copy to etc.. and clean up

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2024, 12:01am UTC](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339/3 "2024-02-01T00:01:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
