Hi Elastic,
Geo IP Plugin is not populating correct information. and for some of the IPs it is not showing the City Name.
Ex: 170.251.154.205 This IP belongs to Bangalore and India, but in Kibana it is showing as Dallas, USA.
Based on this we generating some alerts, this is in Production and our Support team will take an action on this.
Below is the configuration:
geoip
{
add_tag => [ "GeoIP" ]
source => "public_ip"
add_field => ["[geoip][coordinates]","%{[geoip][longitude]}"]
add_field => ["[geoip][coordinates]","%{[geoip][latitude]}"]
}
mutate
{
convert => [ "[geoip][coordinates]", "float" ]
}