# GEO Grok Question For Auth Log

**URL:** <https://discuss.elastic.co/t/geo-grok-question-for-auth-log/105596>\
**Category:** Logstash\
**Created:** [October 27, 2017, 5:01pm UTC](https://discuss.elastic.co/t/geo-grok-question-for-auth-log/105596 "2017-10-27T17:01:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RichardLaing](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@RichardLaing](https://discuss.elastic.co/u/RichardLaing)\
**Post date:** [October 27, 2017, 5:01pm UTC](https://discuss.elastic.co/t/geo-grok-question-for-auth-log/105596/1 "2017-10-27T17:01:43Z")

</div>

Hi there I am looking for some help with getting GEOIP working with logstash. At present I have a working grok for my auth log however I keep getting "\_geoip\_lookup\_failure" whenever I try to use the following, my question is what I am doing wrong within the code? Also I have installed the geo IP plugin for Logstash and elastic-search and at present I have tired a local / private IP address as I understand the geoip plugin shouldn't attempt to resolve my private range. How do I find what is going wrong?

```
filter {
        if [source] == "/var/log/auth.log" {
               grok {
                    match => {
                        "message" => ["%{TIMESTAMP_ISO8601:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\[%{POSINT:system.auth.pid}\])?: %{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user )?%{DATA:system.auth.user} from %{IPORHOST:system.auth.ssh.ip} port %{NUMBER:system.auth.ssh.port} ssh2(: %{GREEDYDATA:system.auth.ssh.signature})?",
                                       "%{TIMESTAMP_ISO8601:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\[%{POSINT:system.auth.pid}\])?: %{DATA:system.auth.ssh.event} user %{DATA:system.auth.user} from %{IPORHOST:system.auth.ssh.ip}",
                                       "%{TIMESTAMP_ISO8601:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\[%{POSINT:system.auth.pid}\])?: Did not receive identification string from %{IPORHOST:system.auth.ssh.dropped_ip}",
                                       "%{TIMESTAMP_ISO8601:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sudo(?:\[%{POSINT:system.auth.pid}\])?: \s*%{DATA:system.auth.user} :( %{DATA:system.auth.sudo.error} ;)? TTY=%{DATA:system.auth.sudo.tty} ; PWD=%{DATA:system.auth.sudo.pwd} ; USER=%{DATA:system.auth.sudo.user} ; COMMAND=%{GREEDYDATA:system.auth.sudo.command}",
                                       "%{TIMESTAMP_ISO8601:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} groupadd(?:\[%{POSINT:system.auth.pid}\])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}",
                                       "%{TIMESTAMP_ISO8601:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} useradd(?:\[%{POSINT:system.auth.pid}\])?: new user: name=%{DATA:system.auth.useradd.name}, UID=%{NUMBER:system.auth.useradd.uid}, GID=%{NUMBER:system.auth.useradd.gid}, home=%{DATA:system.auth.useradd.home}, shell=%{DATA:system.auth.useradd.shell}$",
                                       "%{TIMESTAMP_ISO8601:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} %{DATA:system.auth.program}(?:\[%{POSINT:system.auth.pid}\])?: %{GREEDYMULTILINE:system.auth.message}"]
                    }
                    pattern_definitions => { "GREEDYMULTILINE" => "(.|\n)*" }
                    remove_field => ["message"]
}
  geoip {
    source => "system.auth.ssh.ip"
    target => "system.auth.ssh.geoip"

 }
}
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 30, 2017, 6:44am UTC](https://discuss.elastic.co/t/geo-grok-question-for-auth-log/105596/2 "2017-10-30T06:44:03Z")

</div>

Did you look in the Logstash log? I'd expect the geoip plugin to log additional information about any failures.

> at present I have tired a local / private IP address as I understand the geoip plugin shouldn't attempt to resolve my private range

I don't think the filter silently avoids RFC1918 addresses.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2017, 6:44am UTC](https://discuss.elastic.co/t/geo-grok-question-for-auth-log/105596/3 "2017-11-27T06:44:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
