# Elastic GeoIP does not work for Linux hosts

**URL:** <https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [February 2, 2025, 7:18pm UTC](https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987 "2025-02-02T19:18:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [February 2, 2025, 7:18pm UTC](https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987/1 "2025-02-02T19:18:05Z")

</div>

Hello,

I have a rather strange problem. My fleet agents that are either Windows or MacOS will send the network flows just fine, including geoid enrichment:

Example:

 ![Screenshot 2025-02-02 at 20.07.58](https://us1.discourse-cdn.com/elastic/original/3X/b/4/b47b3b08d5d16db2f5676473905579abffb789bb.png)

But the flows send by Linux hosts do not contain any geo ip enrichment anymore. I know this worked some time ago so I am not sure what happened.

Example:

 ![Screenshot 2025-02-02 at 19.58.53](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e3e2a145ed55cc3e74547f4da2a6dd80adb6dfc.png)

I searched for anything destination.geo.country: \* and host os linux but no results.

It would be nice if this would work again as some of my detection rules are based on geo ip (e.g. connection of server to suspicious country etc.).

ELK 8.14.0  
Fleet Agents (working and not working) are on   
8.14.0 as well.

Network Capture Integration v1.1.0 (on all agents).

Any help is appreciated.

---

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [February 14, 2025, 8:42pm UTC](https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987/2 "2025-02-14T20:42:41Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 15, 2025, 2:31am UTC](https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987/3 "2025-02-15T02:31:21Z")

</div>

Hmmm, the geoip processes happen in an ingest pipelines on elasticsearch, not on the agent host, so it should be independent of agent Host OS.

First, I would update the Network Capture Integration.

v1.1.0 is nearly 3 years old

the latest is

#### Network Packet Capture version

|Latest version|1.32.1|

Then say that is DNS flow the geoip happens in

`logs-network_traffic.dns-1.32.1-geoip` ingest pipeline which does not operate on Operating System OS

Perhaps upgrade and see if you get different results

---

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [April 1, 2025, 4:20pm UTC](https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987/4 "2025-04-01T16:20:42Z")

</div>

That was indeed a very old version haha. Did not notice that. I have since updated the integration and now it works. Thanks for the help!
