# Displaying two geoips on Kibana Coordinate Map

**URL:** <https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494>\
**Category:** Kibana\
**Created:** [July 11, 2018, 7:32am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494 "2018-07-11T07:32:57Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![hasifsulaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hasifsulaiman/32/96499_2.png) [@hasifsulaiman](https://discuss.elastic.co/u/hasifsulaiman)\
**Post date:** [July 11, 2018, 7:32am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/1 "2018-07-11T07:32:57Z")

</div>

Hi, i'm new with elk stack, and need some help with my problem.

I have read the [topic](https://discuss.elastic.co/t/how-to-create-line-from-source-to-destination-in-map/2343), basically on how to emulate something like an attack map [cyber map](https://www.fireeye.com/cyber-map/threat-map.html), but I'm not sure if it is possible or not.

My objective is to show IP addresses from both source and destination IP if only it is from the internet on a Kibana coordinate map. I'm using the cidr function to add tags for both destination and source ip if it is from internal IP. By doing this, I'm able to filter out IPs from the internet and create a geo location.

This is my logstash conf file

//

```
		filter {
	   grok {
			match => ["message", "%{SYSLOGTIMESTAMP:mytime} %{WORD:unuse1} %{WORD:unuse2}\[%{NUMBER:unuse3}\]\: \[%{NUMBER:sid}\:%{NUMBER:gid}\:%{NUMBER:rev}\] %{DATA:ids_data} \[Classification\: %{DATA:classification}\] \[Priority:\s+%{INT:priority}\] \{%{WORD:ids_proto}\}\s+%{IP:src_ip}\:%{INT:src_port}\s+\-\>\s+%{IP:dst_ip}\:%{INT:dst_port}" ]
		}
		#add tag to source IP which is coming from internal IP
		cidr{
			add_tag => ["internal_ip_source"]
			address => ["%{src_ip}"]
			network => ["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"]
		}
		# create geoip for those IPs without tag
		if [tags] != "internal_ip_source"
		{	
			geoip{
				source => "[src_ip]"
				target => "internet_ip"
				add_field => ["[internet_ip][source_coordinates]", "%{[internet_ip][longitude]}" ]
				add_field => ["[internet_ip][source_coordinates]", "%{[internet_ip][latitude]}" ]
			}
			mutate {
				convert => ["[internet_ip][source_coordinates]", "float"]
			}
		}
		
		
		
		#add tag to destination IP which is coming from internal IP
		cidr{
			add_tag => ["internal_ip_destination"]
			address => ["%{dst_ip}"]
			network => ["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"]
		}
		# create geoip for those IPs without tag
		if [tags] != "internal_ip_source"
		{	
			geoip{
				source => "[dst_ip]"
				target => "internet_ip"
				add_field => ["[internet_ip][destination_coordinates]", "%{[internet_ip][longitude]}" ]
				add_field => ["[internet_ip][destination_coordinates]", "%{[internet_ip][latitude]}" ]
			}
			mutate {
				convert => ["[internet_ip][destination_coordinates]", "float"]
			}
		}
		date {
			match => ["mytime", "MMM dd HH:mm:ss", "MMM d HH:mm:ss", "MMMM dd HH:mm:ss", "ISO8601"] #need to match the date log pattern exactly 100 percent all the spaces, special characters 
			target => "@timestamp"
		}
		}

```

This is part of my mapping

```
 "internet_ip" : {
      "dynamic": true,
      "properties" : {
        "ip": { "type": "ip" },
        "location" : { "type" : "geo_point" },
		"source_coordinates" : { "type" : "geo_point" },
		"destination_coordinates" : { "type" : "geo_point" },
        "latitude" : { "type" : "half_float" },
        "longitude" : { "type" : "half_float" }
      }
    }

```

I tried to run it on kibana, but source\_coordinates and destination\_coordinates data type does not change to geo\_point.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 11, 2018, 7:38am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/2 "2018-07-11T07:38:36Z")

</div>

> [@hasifsulaiman](#):
>
> This is part of my mapping

Is that the active mapping from the index, or one you are applying before indexing?

---

<div class="post-metadata">

**Author:** ![hasifsulaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hasifsulaiman/32/96499_2.png) [@hasifsulaiman](https://discuss.elastic.co/u/hasifsulaiman)\
**Post date:** [July 11, 2018, 7:57am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/4 "2018-07-11T07:57:05Z")

</div>

im not sure which is which, most probably im applying it before indexing, is it possible to create two geo location?

---

<div class="post-metadata">

**Author:** ![hasifsulaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hasifsulaiman/32/96499_2.png) [@hasifsulaiman](https://discuss.elastic.co/u/hasifsulaiman)\
**Post date:** [July 11, 2018, 7:57am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/5 "2018-07-11T07:57:44Z")

</div>

```
  elasticsearch {
 hosts => "localhost:9200"
 index => "snort_tcp%{+YYYY.MM.dd}"
 manage_template => true
 template => "c:\Program Files\logstash-6.3.0\templates\snorttcp.json"
 template_name => "snort_tcp*" } stdout { codec => rubydebug } }
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 11, 2018, 8:04am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/6 "2018-07-11T08:04:43Z")

</div>

You can have multiple geopoints, yes. You should look at the `_mapping` endpoint for your index to see what has been applied.

---

<div class="post-metadata">

**Author:** ![hasifsulaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hasifsulaiman/32/96499_2.png) [@hasifsulaiman](https://discuss.elastic.co/u/hasifsulaiman)\
**Post date:** [July 11, 2018, 8:36am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/7 "2018-07-11T08:36:25Z")

</div>

to be honest, im not sure what to look for, so sorry to trouble you, from \_mapping, i got something similar with what has been defined on my snorttcp.json with changing index something like "snort\_tcp2018.06.05" , "snort\_tcp2018.06.15"

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 11, 2018, 9:25am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/8 "2018-07-11T09:25:56Z")

</div>

If you can call one index with that endpoint and then paste the output, that'll help.

Just make sure you format it with code tags (backticks) or use the `</>` button.

---

<div class="post-metadata">

**Author:** ![hasifsulaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hasifsulaiman/32/96499_2.png) [@hasifsulaiman](https://discuss.elastic.co/u/hasifsulaiman)\
**Post date:** [July 12, 2018, 12:13am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/9 "2018-07-12T00:13:29Z")

</div>

```
  "snort_tcp2018.07.11": {
"mappings": {
  "doc": {
    "dynamic_templates": [
      {
        "message_field": {
          "path_match": "message",
          "match_mapping_type": "string",
          "mapping": {
            "norms": false,
            "type": "text"
          }
        }
      },
      {
        "string_fields": {
          "match": "*",
          "match_mapping_type": "string",
          "mapping": {
            "fields": {
              "keyword": {
                "ignore_above": 256,
                "type": "keyword"
              }
            },
            "norms": false,
            "type": "text"
          }
        }
      }
    ],
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "@version": {
        "type": "keyword"
      },
      "beat": {
        "properties": {
          "hostname": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "name": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "version": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      },
      "dst_geoip": {
        "dynamic": "true",
        "properties": {
          "ip": {
            "type": "ip"
          },
          "latitude": {
            "type": "half_float"
          },
          "location": {
            "type": "geo_point"
          },
          "longitude": {
            "type": "half_float"
          }
        }
      },
      "host": {
        "properties": {
          "name": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      },
      "input": {
        "properties": {
          "type": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      },
      "message": {
        "type": "text",
        "norms": false
      },
      "offset": {
        "type": "long"
      },
      "prospector": {
        "properties": {
          "type": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      },
      "source": {
        "type": "text",
        "norms": false,
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "src_geoip": {
        "dynamic": "true",
        "properties": {
          "ip": {
            "type": "ip"
          },
          "latitude": {
            "type": "half_float"
          },
          "location": {
            "type": "geo_point"
          },
          "longitude": {
            "type": "half_float"
          }
        }
      },
      "syslog_hostname": {
        "type": "text",
        "norms": false,
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "syslog_message": {
        "type": "text",
        "norms": false,
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "syslog_pid": {
        "type": "text",
        "norms": false,
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "syslog_program": {
        "type": "text",
        "norms": false,
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "syslog_timestamp": {
        "type": "text",
        "norms": false,
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "tags": {
        "type": "text",
        "norms": false,
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }
    }
  },
```

---

<div class="post-metadata">

**Author:** ![hasifsulaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hasifsulaiman/32/96499_2.png) [@hasifsulaiman](https://discuss.elastic.co/u/hasifsulaiman)\
**Post date:** [July 12, 2018, 12:14am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/10 "2018-07-12T00:14:29Z")

</div>

```
 "_default_": {
    "dynamic_templates": [
      {
        "message_field": {
          "path_match": "message",
          "match_mapping_type": "string",
          "mapping": {
            "norms": false,
            "type": "text"
          }
        }
      },
      {
        "string_fields": {
          "match": "*",
          "match_mapping_type": "string",
          "mapping": {
            "fields": {
              "keyword": {
                "ignore_above": 256,
                "type": "keyword"
              }
            },
            "norms": false,
            "type": "text"
          }
        }
      }
    ],
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "@version": {
        "type": "keyword"
      },
      "dst_geoip": {
        "dynamic": "true",
        "properties": {
          "ip": {
            "type": "ip"
          },
          "latitude": {
            "type": "half_float"
          },
          "location": {
            "type": "geo_point"
          },
          "longitude": {
            "type": "half_float"
          }
        }
      },
      "src_geoip": {
        "dynamic": "true",
        "properties": {
          "ip": {
            "type": "ip"
          },
          "latitude": {
            "type": "half_float"
          },
          "location": {
            "type": "geo_point"
          },
          "longitude": {
            "type": "half_float"
          } 
       } 
   }
   } 
   }
  } 
  }
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2018, 12:16am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/11 "2018-07-12T00:16:04Z")

</div>

So it's mapped fine then.  
I don't think you can currently have more than one geopoint field on a map though, you may need to look at using the Vega plugin for that instead.

---

<div class="post-metadata">

**Author:** ![hasifsulaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hasifsulaiman/32/96499_2.png) [@hasifsulaiman](https://discuss.elastic.co/u/hasifsulaiman)\
**Post date:** [July 12, 2018, 2:17am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/12 "2018-07-12T02:17:35Z")

</div>

what if i store both source ip and destination ip to target =\> geoip

```
if [tags] != "internal_ip_source"
		{	
			geoip {
				source => "[src_ip]"
				target => "geoip"
			}
		}

if [tags] != "internal_ip_source"
		{	
			geoip {
				source => "[dst_ip]"
				target => "geoip"
			}
		}

```

and the mapping would be something like

```
"geoip" : {
      "dynamic": true,
      "properties" : {
        "ip": { "type": "ip" },
        "location" : { "type" : "geo_point" },
        "latitude" : { "type" : "half_float" },
        "longitude" : { "type" : "half_float" }
      }
    }

```

logically, it would just store both IP addresses right?

Btw, thanks for your help, i'll try to do some research on your recommendation.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2018, 2:46am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/13 "2018-07-12T02:46:43Z")

</div>

> [@hasifsulaiman](#):
>
> logically, it would just store both IP addresses right?

But in the one geo field, which would be overwritten by whichever of your filters runs second.

---

<div class="post-metadata">

**Author:** ![kevinkeeneyjr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevinkeeneyjr/32/27270_2.png) [@kevinkeeneyjr](https://discuss.elastic.co/u/kevinkeeneyjr)\
**Post date:** [July 19, 2018, 8:34pm UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/14 "2018-07-19T20:34:35Z")

</div>

This project, might help provide some insights:

> **[elastickent/mapster](https://github.com/elastickent/mapster)**
>
> mapster - Live events map as a Kibana plugin

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [August 4, 2018, 10:57am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/15 "2018-08-04T10:57:15Z")

</div>

Mapster is really cool. Too bad it isn't maintained. ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2018, 10:57am UTC](https://discuss.elastic.co/t/displaying-two-geoips-on-kibana-coordinate-map/139494/16 "2018-09-01T10:57:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
