# Geoip database format

**URL:** <https://discuss.elastic.co/t/geoip-database-format/135838>\
**Category:** Logstash\
**Created:** [June 14, 2018, 6:56am UTC](https://discuss.elastic.co/t/geoip-database-format/135838 "2018-06-14T06:56:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vitalijs\_Grinbergs](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@Vitalijs\_Grinbergs](https://discuss.elastic.co/u/Vitalijs_Grinbergs)\
**Post date:** [June 14, 2018, 6:56am UTC](https://discuss.elastic.co/t/geoip-database-format/135838/1 "2018-06-14T06:56:19Z")

</div>

Is there a way to use updated geoip database in .dat format?  
I've used mmdb tools to convert .mmdb ti .csv and updated it with private IP subnets and geolocation according to [https://github.com/threatstream/mhn/wiki/Customizing-Maxmind-IP-Geo-DB-for-Internal-Networks](https://github.com/threatstream/mhn/wiki/Customizing-Maxmind-IP-Geo-DB-for-Internal-Networks)  
As a result I've got .dat file.  
That updated .dat file I've put in logstash filter.  
geoip {  
source =\> "clientip"  
database =\> "/usr/share/logstash/mmcity.dat"

After logstash restart, the logstash-plain.log has ERROR: "The database provided is invalid or co  
rrupted."

**Please guide me to correct topic where I can use my updated mmcity.dat database.**

logstash version 6.3

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2018, 7:09am UTC](https://discuss.elastic.co/t/geoip-database-format/135838/2 "2018-07-12T07:09:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
