# Create Custom geoip database for Logstash 5.2

**URL:** <https://discuss.elastic.co/t/create-custom-geoip-database-for-logstash-5-2/79473>\
**Category:** Logstash\
**Created:** [March 21, 2017, 4:50pm UTC](https://discuss.elastic.co/t/create-custom-geoip-database-for-logstash-5-2/79473 "2017-03-21T16:50:43Z")\
**Posts on this page:** 1\
**Showing post:** 20

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 29, 2017, 1:51pm UTC](https://discuss.elastic.co/t/create-custom-geoip-database-for-logstash-5-2/79473/20 "2017-03-29T13:51:27Z")

</div>

Last thing please : I find a mistake with my IP

If in my yaml file I have those 2 ip :

```
'10.12.4.*': '{"geoip": {"latitude": 43.667805, "longitude": 7.213004, "location": [7.213004, 43.667805]}}'
'10.12.49.*': '{"geoip": {"latitude": 43.698512, "longitude": 7.278436, "location": [7.278436, 43.698512]}}'

```

When I ask for example '10.12.49.18' (my second line) logstash add the values of my first line.

I tried to use a regex but nothing happens

```
input { stdin {} }

filter{
  if [message] =~ /^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])*$/ {
	translate {
	    exact => true
	    regex => true
	    dictionary_path => "/etc/logstash/mutate/nca-geo.yml"
	    field => "message"
	}

	json {
	    source => "translation"
	}
  } 
}

output { stdout { codec => rubydebug} }

```

Thank you

---

_[View the full topic](https://discuss.elastic.co/t/create-custom-geoip-database-for-logstash-5-2/79473)._
