# \_geoip\_database\_unavailable\_GeoLite2-ASN.mmdb

**URL:** <https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [April 25, 2023, 8:40pm UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772 "2023-04-25T20:40:47Z")\
**Posts on this page:** 4\
**Page:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 26, 2023, 5:04am UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772/22 "2023-04-26T05:04:57Z")

</div>

Sorry but that is not the correct part of the logs... there are many many logs perhaps take the file

`grep -i geo my-application.log`

and show those results...

I am asking internally... I am seeing some inconsistency in 8.7.0... but oddly _ **not** _ with your version the geo dbs loaded right away...

BTW this is what geostats should look like... seeing if there is a command to force reload..

```auto
curl 'localhost:9200/_ingest/geoip/stats?pretty'
{
  "stats" : {
    "successful_downloads" : 3,
    "failed_downloads" : 0,
    "total_download_time" : 5082,
    "databases_count" : 3,
    "skipped_updates" : 0,
    "expired_databases" : 0
  },
  "nodes" : {
    "3-C7p0V6TZegryYhcK7ayA" : {
      "databases" : [
        {
          "name" : "GeoLite2-City.mmdb"
        },
        {
          "name" : "GeoLite2-Country.mmdb"
        },
        {
          "name" : "GeoLite2-ASN.mmdb"
        }
      ],
      "files_in_temp" : [
        "GeoLite2-ASN.mmdb_elastic-geoip-database-service-agreement-LICENSE.txt",
        "GeoLite2-ASN.mmdb_LICENSE.txt",
        "GeoLite2-City.mmdb_LICENSE.txt",
        "GeoLite2-Country.mmdb_elastic-geoip-database-service-agreement-LICENSE.txt",
        "GeoLite2-ASN.mmdb",
        "GeoLite2-City.mmdb_COPYRIGHT.txt",
        "GeoLite2-City.mmdb",
        "GeoLite2-City.mmdb_elastic-geoip-database-service-agreement-LICENSE.txt",
        "GeoLite2-Country.mmdb_LICENSE.txt",
        "GeoLite2-Country.mmdb",
        "GeoLite2-ASN.mmdb_COPYRIGHT.txt",
        "GeoLite2-Country.mmdb_COPYRIGHT.txt",
        "GeoLite2-City.mmdb_README.txt"
      ]
    }
  }
}

```

I have one other thing you can try...

Try to disable then reenable

Disable the geoip databases

```auto
PUT _cluster/settings
{
  "persistent": {
    "ingest.geoip.downloader.enabled" : false
  }
}

GET _cat/indices/.ge*?v

GET _ingest/geoip/stats

```

Wait about 2 mins then re-enable

```auto
PUT _cluster/settings
{
  "persistent": {
    "ingest.geoip.downloader.enabled" : true
  }
}

GET _cat/indices/.ge*?v

GET _ingest/geoip/stats

```

Let me know if that works

You also try setting false / true in elasticsearch.yml and start stop see if that works

---

<div class="post-metadata">

**Author:** ![Akjal](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Post date:** [April 26, 2023, 12:44pm UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772/23 "2023-04-26T12:44:51Z")

</div>

> [@stephenb](#):
>
> grep -i geo my-application.log

here is the log as you suggested after inputting `grep -i geo my-application.log` :

```auto
org.elasticsearch.ElasticsearchException: not all primary shards of [.geoip_databases] index are active
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.updateDatabases(GeoIpDownloader.java:134) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.runDownloader(GeoIpDownloader.java:274) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloaderTaskExecutor.nodeOperation(GeoIpDownloaderTaskExecutor.java:102) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloaderTaskExecutor.nodeOperation(GeoIpDownloaderTaskExecutor.java:48) ~[?:?]
[2023-04-26T02:01:39,499][WARN][o.e.i.g.GeoIpDownloader] [node-1] could not delete old chunks for geoip database [GeoLite2-Country.mmdb]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.deleteOldChunks(GeoIpDownloader.java:200) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.lambda$cleanDatabases$4(GeoIpDownloader.java:295) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.cleanDatabases(GeoIpDownloader.java:302) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.runDownloader(GeoIpDownloader.java:280) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloaderTaskExecutor.nodeOperation(GeoIpDownloaderTaskExecutor.java:102) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloaderTaskExecutor.nodeOperation(GeoIpDownloaderTaskExecutor.java:48) ~[?:?]
Caused by: org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.geoip_databases][0]]. Consider using `allow_partial_search_results` setting to bypass this error.
[2023-04-26T02:01:40,508][WARN][o.e.i.g.GeoIpDownloader] [node-1] could not delete old chunks for geoip database [GeoLite2-City.mmdb]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.deleteOldChunks(GeoIpDownloader.java:200) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.lambda$cleanDatabases$4(GeoIpDownloader.java:295) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.cleanDatabases(GeoIpDownloader.java:302) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloader.runDownloader(GeoIpDownloader.java:280) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloaderTaskExecutor.nodeOperation(GeoIpDownloaderTaskExecutor.java:102) ~[?:?]
        at org.elasticsearch.ingest.geoip.GeoIpDownloaderTaskExecutor.nodeOperation(GeoIpDownloaderTaskExecutor.java:48) ~[?:?]
Caused by: org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.geoip_databases][0]]. Consider using `allow_partial_search_results` setting to bypass this error.

```

this is the same output as before when i run curl 'localhost:9200/\_ingest/geoip/stats?pretty'

```auto
{
  "stats" : {
    "successful_downloads" : 0,
    "failed_downloads" : 1,
    "total_download_time" : 0,
    "databases_count" : 0,
    "skipped_updates" : 0,
    "expired_databases" : 3
  },
  "nodes" : { }
}

```

---

<div class="post-metadata">

**Author:** ![Akjal](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Post date:** [April 26, 2023, 1:34pm UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772/24 "2023-04-26T13:34:16Z")

</div>

> [@stephenb](#):
>
> ```auto
> PUT _cluster/settings
> {
> "persistent": {
> "ingest.geoip.downloader.enabled" : true
> }
> }
> 
> ```

Thank you so much @stephenb !!!, , it is working now!, I disabled and reanabled the geoip.downloader as you outlined above and it worked. Miraculous 😄

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2023, 3:34pm UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772/25 "2023-05-24T15:34:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772.md?page=1)
