# ECS expect \`target\` value

**URL:** <https://discuss.elastic.co/t/ecs-expect-target-value/308652>\
**Category:** Logstash\
**Created:** [July 1, 2022, 10:46am UTC](https://discuss.elastic.co/t/ecs-expect-target-value/308652 "2022-07-01T10:46:14Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [July 1, 2022, 10:35pm UTC](https://discuss.elastic.co/t/ecs-expect-target-value/308652/3 "2022-07-01T22:35:30Z")

</div>

Hi Badger,

Thanks for your help!

I've tried it and the log message complains about the same thing:

```auto
[WARN][logstash.filters.geoip][3_sflow] ECS expect `target` value `[source][geo][ip]` in ["client", "destination", "host", "observer", "server", "source"]

```

I'm not sure what format the ip fields should be in, can't really find an example.

I've tried renaming dst\_ip and src\_ip fields to source.ip and destination.ip - the reasoning behind is that filebeat netflow module uses this naming convention but no luck with that either.

I've seen this post already and if i disable ecs compatibility I'm guessing it will work, but I'd like to get it working with ECS, if possible 🙂

> [@Geoip stopped consolidating coordinates after logstash upgrade to 8.0](https://discuss.elastic.co/t/geoip-stopped-consolidating-coordinates-after-logstash-upgrade-to-8-0/298067):
>
> My logstash for geo tagging IPs are failing after logstash upgrade 8.0. Here's a snippet , i get the lat and lon values , but cant seem to get into the "destlocation" field "Dest\_IP" =\> { "geo" =\> { "country\_name" =\> "United States", "location" =\> { "lat" =\> 37.751, "lon" =\> -97.822 }, "timezone" =\> "America/Chicago", "country\_iso\_code" =\> "US", "conti…

---

_[View the full topic](https://discuss.elastic.co/t/ecs-expect-target-value/308652)._
