# Creating geoip data for internal networks

**URL:** <https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729>\
**Category:** Logstash\
**Created:** [May 15, 2015, 4:23am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729 "2015-05-15T04:23:52Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![JimCheetham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimcheetham/32/44843_2.png) [@JimCheetham](https://discuss.elastic.co/u/JimCheetham)\
**Post date:** [May 15, 2015, 4:23am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/1 "2015-05-15T04:23:52Z")

</div>

I have many internal users, and both public and private address space in use. I would like to be able to usefully separate my networks from the country we're in, and provide sensible geoip data.

For my public range, I can easily fix the text fields I want to change (eg we get the wrong timezone, but that doesn't affect @timestamp; and I change [geoip][country\_name] to a private value), and for my 10.0.0.0/8 network I can create the [geoip] structure I need.

Unfortunately I can't figure out how to make a geo\_point value that gets in to Elasticsearch ... I need to create a geo\_point for the internal network, and would like to fix the existing ones for the public range. I keep ending up with {"type":"double"} instead of {"type":"geopoint"}, even when I specify an output template for Elasticsearch.

Can someone please point me at an example of creating a geo\_point from scratch, and getting it into ES?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 15, 2015, 5:52am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/2 "2015-05-15T05:52:04Z")

</div>

Basically a geo point should be lat then lon, and if the field it mapped as a geopoint then it should all fall into place.

Can you post your relevant LS config excerpts? The mapping sections might also be useful too.

---

<div class="post-metadata">

**Author:** ![JimCheetham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimcheetham/32/44843_2.png) [@JimCheetham](https://discuss.elastic.co/u/JimCheetham)\
**Post date:** [August 10, 2015, 4:29am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/3 "2015-08-10T04:29:05Z")

</div>

After a long time away from this issue, I've managed to get the right setup.

In my logstash config, after I've called `geoip {}` I look for my IP address ranges and manually repopulate the various fields. I'm effectively declaring a new country.

```
if [srcip] =~ /^139\.80\./ or [srcip] =~ /^10\./ {
   mutate { replace => { "[geoip][timezone]" => "Pacific/Auckland" } }
   mutate { replace => { "[geoip][country_name]" => "University of Otago" } }
   mutate { replace => { "[geoip][country_code2]" => "UO" } }
   mutate { replace => { "[geoip][country_code3]" => "UoO" } }
   mutate { remove_field => ["[geoip][location]" ] }
   mutate { add_field => { "[geoip][location]" => "170.525" } }
   mutate { add_field => { "[geoip][location]" => "-45.865" } }
   mutate { convert => ["[geoip][location]", "float" ] }
   mutate { replace => ["[geoip][latitude]", -45.856 ] }
   mutate { convert => ["[geoip][latitude]", "float" ] }
   mutate { replace => ["[geoip][longitude]", 170.525 ] }
   mutate { convert => ["[geoip][longitude]", "float" ] }
}
```

To help keep me honest (actually, to make sure that all my settings are visible in the configuration) I explicitly set a template when writing to ES, rather than rely on state that's already there.

```
elasticsearch { embedded => "false"
  cluster => "myclustername"
  protocol => "transport"
  host => "indexing host"
  index => "test" # index name must be in lowercase!
  template => "/etc/logstash/template.d/test"
  template_name => "test"
  template_overwrite => "true"
}
```

(Every time I drop this index, the new template will be used to re-create it.)

For my purposes, I'm using the template to switch off string analyzing (most of the fields are log data and analysis doesn't help), and to make sure I get geo\_points done properly. Here's the full template from the dev box :-

```
{
  "order" : 0,
  "template" : "test*",
  "settings" : { "index.refresh_interval" : "5s" },
  "mappings" : {
    "_default_" : {
      "dynamic_templates" : [
        {
          "message_field" : {
            "mapping" : { "index" : "analyzed", "omit_norms" : true, "type" : "string" },
            "match_mapping_type" : "string",
            "match" : "message" }
          },
        {
          "string_fields" : {
            "mapping" : { "index" : "not_analyzed", "ignore_above" : 256, "type" : "string" },
            "match_mapping_type" : "string",
            "match" : "*" }
          }
       ],
      "properties" : {
        "geoip" : {
          "dynamic" : true,
          "path" : "full",
          "properties" : { "location" : { "type" : "geo_point" } },
          "type" : "object" },
        "@version" : { "index" : "not_analyzed", "type" : "string" }
      },
      "_all" : { "enabled" : true }
    }
  },
  "aliases" : { }
}
```

The end result is a custom country, with a geo-location that separates my network from the users in the same city (although the point on the map when you zoom in isn't as accurate as I want it to be, I don't think I'll worry about that!)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2015, 5:23am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/4 "2015-08-10T05:23:47Z")

</div>

That's super awesome!

Nice work @jim 😃

---

<div class="post-metadata">

**Author:** ![inf2ravikumar](https://avatars.discourse-cdn.com/v4/letter/i/958977/32.png) [@inf2ravikumar](https://discuss.elastic.co/u/inf2ravikumar)\
**Post date:** [February 29, 2016, 4:38pm UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/5 "2016-02-29T16:38:44Z")

</div>

Good Morning Little help Here I have difficulty to maluplate city names in kibana 3 ,  
I have servers in internal network i have configured my logstash configuration as follows

if "a4" in [site] {mutate {add\_field =\> { city =\> "Chicago" st =\> "IL" lat =\> "41.7897125" lng =\> "-87.68365" division =\> "Central" region =\> "Chicago" }}}

else if "ab" in [site] {mutate {add\_field =\> { city =\> "Albuquerque" st =\> "NM" lat =\> "35.1101413" lng =\> "-106.5579597" division =\> "Western" region =\> "Mile High" }}}

else if "ag" in [site] {mutate {add\_field =\> { city =\> "Augusta" st =\> "GA" lat =\> "33.4734978" lng =\> "-82.0105148" division =\> "Central" region =\> "Big South" }}}

Results  
I'm able to see All Events with the data table Every host = state  
City = Augusta  
Division = Central

Please help to understand as pretty new to using logstash configuration.

Thanks in Advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 29, 2016, 6:03pm UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/6 "2016-02-29T18:03:09Z")

</div>

@inf2ravikumar, please start a new thread for your unrelated question.

---

<div class="post-metadata">

**Author:** ![inf2ravikumar](https://avatars.discourse-cdn.com/v4/letter/i/958977/32.png) [@inf2ravikumar](https://discuss.elastic.co/u/inf2ravikumar)\
**Post date:** [February 29, 2016, 6:18pm UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/7 "2016-02-29T18:18:31Z")

</div>

Sure I'will do that sorry about it.

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 9:59pm UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/8 "2016-08-17T21:59:25Z")

</div>

> [@JimCheetham](#):
>
> if [srcip] =~ /^139.80./ or [srcip] =~ /^10./ {

Dosen't work:  
`The given configuration is invalid. Reason: Expected one of #, =\> at line 34, column 8 (byte 2419) after filter  
...

if {:level=\>:fatal}`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 18, 2016, 8:45am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/9 "2016-08-18T08:45:07Z")

</div>

Please give more context. There's nothing wrong the quoted line (except that the regexp is a bit sloppy and should escape the dots).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2016, 8:55am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/10 "2016-08-18T08:55:59Z")

</div>

There's another thread on this one.

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 18, 2016, 9:06am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/11 "2016-08-18T09:06:17Z")

</div>

> [@TileMap, GeoIP for RFC1918 addresses](https://discuss.elastic.co/t/tilemap-geoip-for-rfc1918-addresses/58247/3):
>
> geoip { source =\> "client\_address" target =\> "geoip" database =\> "/etc/logstash/conf.d/geo/GeoLiteCity.dat" add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ] add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ] if [client\_address] =~ /^10\./ { mutate { replace =\> { "[geoip][timezone]" =\> "Pacific/Auckland" } } mutate { replace =\> { "[geoip][country\_name]" =\> "University of Otago" } } …

---

<div class="post-metadata">

**Author:** ![Joshua\_Fernandes](https://avatars.discourse-cdn.com/v4/letter/j/82dd89/32.png) [@Joshua\_Fernandes](https://discuss.elastic.co/u/Joshua_Fernandes)\
**Post date:** [May 15, 2017, 11:42pm UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/12 "2017-05-15T23:42:48Z")

</div>

Hi @bastianhoss,  
Unsure if you fixed this or not, but I ran into this issue yesterday so I'll post what I wound up doing for future searches...

```
 if [client_address] =~ /^10\./ {
  mutate { replace => { "[geoip][timezone]" => "Pacific/Auckland" } }
  mutate { replace .....
} else {
  geoip {
    source => "client_address"
    target => "geoip"
    add_tag => ["nginx-geoip"]
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:26am UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/13 "2017-07-06T04:26:34Z")

</div>


