maof97  
                
                  
                    February 2, 2025,  7:18pm
                   
                  1 
               
             
            
              Hello,
I have a rather strange problem. My fleet agents that are either Windows or MacOS will send the network flows just fine, including geoid enrichment:
Example:
But the flows send by Linux hosts do not contain any geo ip enrichment anymore. I know this worked some time ago so I am not sure what happened.
Example:
I searched for anything destination.geo.country: * and host os linux but no results.
It would be nice if this would work again as some of my detection rules are based on geo ip (e.g. connection of server to suspicious country etc.).
ELK 8.14.0
Network Capture Integration v1.1.0 (on all agents).
Any help is appreciated.
             
            
              
            
           
          
            
              
                stephenb  
              
                  
                    February 15, 2025,  2:31am
                   
                  3 
               
             
            
              Hmmm, the geoip processes happen in an ingest pipelines on elasticsearch, not on the agent host, so it should be independent of agent Host OS.
First, I would update the Network Capture Integration.
v1.1.0 is nearly 3 years old
the latest is
|Latest version|1.32.1|
Then say that is DNS flow the geoip happens in
logs-network_traffic.dns-1.32.1-geoip ingest pipeline which does not operate on Operating System OS
Perhaps upgrade and see if you get different results
             
            
              
            
           
          
            
              
                maof97  
              
                  
                    April 1, 2025,  4:20pm
                   
                  4 
               
             
            
              That was indeed a very old version haha. Did not notice that. I have since updated the integration and now it works. Thanks for the help!