# Elastic - Geo Enrichment

**URL:** <https://discuss.elastic.co/t/elastic-geo-enrichment/369756>\
**Category:** Kibana\
**Created:** [October 29, 2024, 5:02pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756 "2024-10-29T17:02:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [October 29, 2024, 5:02pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/1 "2024-10-29T17:02:45Z")

</div>

Is there a way to do enrichment of an area code. I am ingesting phone call data and would like to get more insights into the location (not provided within the actual data).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 29, 2024, 8:32pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/2 "2024-10-29T20:32:40Z")

</div>

If you have a correspondance map/table, yes you could do something like this.

I wrote 3 blog posts related to enrichment, depending on "where" you want to do this:

> **[Enrich your Elasticsearch documents within Elasticsearch](https://www.elastic.co/blog/enrich-your-elasticsearch-documents-within-elasticsearch)**
>
> With Elasticsearch, we know that joins should be done "at index time" instead of query time. This blog post starts a series of three posts as there are many approaches we can take within the Elastic e...

> **[Enrich your Elasticsearch documents with Logstash](https://www.elastic.co/blog/enrich-your-elasticsearch-documents-with-logstash)**
>
> Using a jdbc static filter connected to Elasticsearch might speed up your Logstash enrichment pipeline....

> **[Enrich your Elasticsearch documents from the edge](https://www.elastic.co/blog/enrich-your-elasticsearch-documents-from-the-edge)**
>
> Using enrichment from the edge reduces the work to be performed by Elasticsearch. Learn how to implement this technique with the Elastic Agent....

Hope this could help.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 29, 2024, 8:32pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/3 "2024-10-29T20:32:52Z")

</div>

Removed #datastreams

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [October 29, 2024, 8:50pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/4 "2024-10-29T20:50:03Z")

</div>

Thanks @dadoonet !  
So from my understanding I would need to supply the geo information through another index?  
I assumed there was like a geo database that elastic might have.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 29, 2024, 9:36pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/5 "2024-10-29T21:36:32Z")

</div>

Not for phone Numbers.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [October 29, 2024, 9:37pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/6 "2024-10-29T21:37:43Z")

</div>

what about area codes? I was thinking of parsing out the area code from the phone number and doing geo analysis

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 29, 2024, 11:34pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/7 "2024-10-29T23:34:41Z")

</div>

Nothing related to phone numbers, including area codes AFAIK.  
If you have such a database, you can build on the links I shared using indeed another index for lookups at index time.

---

<div class="post-metadata">

**Author:** ![Keith\_Massey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_massey/32/83666_2.png) [@Keith\_Massey](https://discuss.elastic.co/u/Keith_Massey)\
**Post date:** [October 30, 2024, 1:16pm UTC](https://discuss.elastic.co/t/elastic-geo-enrichment/369756/8 "2024-10-30T13:16:16Z")

</div>

If you want to see exactly which fields are supported for each geo database type that we can handle, take a look at [elasticsearch/modules/ingest-geoip/src/test/java/org/elasticsearch/ingest/geoip/MaxMindSupportTests.java at main · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/blob/main/modules/ingest-geoip/src/test/java/org/elasticsearch/ingest/geoip/MaxMindSupportTests.java). It's not the most user-friendly thing to read, but the things in `*_SUPPORTED_FIELDS` sets are the fields that are in geo databases that we support, and the `*_UNSUPPORTED_FIELDS` sets are the things that are in geo databases but that we do not support. As @dadoonet said, there is nothing related to phone numbers in those databases at all.
