# Geoip doen't create field correctly

**URL:** <https://discuss.elastic.co/t/geoip-doent-create-field-correctly/212012>\
**Category:** Logstash\
**Created:** [December 16, 2019, 1:25pm UTC](https://discuss.elastic.co/t/geoip-doent-create-field-correctly/212012 "2019-12-16T13:25:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [December 16, 2019, 1:25pm UTC](https://discuss.elastic.co/t/geoip-doent-create-field-correctly/212012/1 "2019-12-16T13:25:49Z")

</div>

I create this filter

```
filter {
# Filter only CEF logs here
  if "syslog" in [tags]{
    # Manipulate the message
    mutate {
         # Saved the original message into a temporary field
         add_field => { "tmp_message" => "%{message}" }
         # splits message on the "|" and has index numbers
         split => ["message", "|"]
         # SAMPLE

         # generate fields for the CEF header
         add_field => { "[cef][version]" => "%{[message][0]}" }
         add_field => { "[cef][device][vendor]" => "%{[message][1]}" }
         add_field => { "[cef][device][product]" => "%{[message][2]}" }
         add_field => { "[cef][device][version]" => "%{[message][3]}" }
         add_field => { "[cef][device][event_class_id]" => "%{[message][4]}" }
         add_field => { "[cef][name]" => "%{[message][5]}" }
         add_field => { "[cef][severity]" => "%{[message][6]}" }
         add_tag => ["CEF-Firewall"]
    }
    # Parse the message with field=value formats for Firewall
    kv {
        # Note: values with spaces are lost (still getting there)
         field_split => " "
         trim_key => "<>\[\], "
         trim_value => "<>\[\],"
         # Only included the fields which are of interest (dont need everything)
         allow_duplicate_values => false
         include_keys => ["act","rt","spt","dpt","match_id","rule_action","ifnam e","dst","inzone","outzone","product","proto","service_id","src","duser","suser" ,"shost","dhost"]
    }
    prune {
         whitelist_values => ["match_id", "^[0-9]{3}$" ]
    }
    mutate {
        # Rename fields to cef_field_names
        rename => ["act", "[event][action]"]
        rename => ["rt", "[cef][time]"]
        rename => ["spt", "[cef][source][port]"]
        rename => ["dpt", "[cef][destination][port]"]
        rename => ["match_id","[cef][rule][number]"]
        rename => ["rule_action","[cef][rule][action]"]
        rename => ["dst", "[cef][destination][geoip][ip]"]
        rename => ["ifname","[cef][interface]"]
        rename => ["inzone","[cef][source][zone]"]
        rename => ["outzone","[cef][destination][zone]"]
        rename => ["product","[cef][device][product2]"]
        rename => ["proto", "[cef][network][transport]"]
        rename => ["service_id", "[cef][service]"]
        rename => ["src", "[cef][source][geoip][ip]"]
        rename => ["suser", "[cef][source][user]"]
        rename => ["duser", "[cef][destination][user]"]
        rename => ["shost", "[cef][source][host]"]
        rename => ["dhost", "[cef][destination][host]"]

        # Revert original message and remove temporary field
        replace => { "message" => "%{tmp_message}" }
        remove_field => ["tmp_message"]
   }
   geoip {
        source => "[cef][source][geoip][ip]"
        target => "[cef][source][geoip][location]"
   }
   geoip {
        source => "[cef][destination][geoip][ip]"
        target => "[cef][destination][geoip][location]"
   }
   date {
      match => ["[cef][time]","UNIX_MS"]
      remove_field => ["[cef][time]" ]
   }
 }
}

```

I have problem with geoip: the processor is applied but the I don't found in my index the field geo\_point.

The output is the following

```
output {
 if "syslog" in [tags]{
    elasticsearch {
      hosts => ["elasticsearch:9200"]
      index => "cef-%{+YYYY.MM.dd}"
# index => "logstash-%{+YYYY.MM.dd}"
      codec => "plain"
      workers => 1
      manage_template => true
      template_name => "cef"
# template_name => "logstash"
      template_overwrite => false
      ssl => true
      cacert => "/tmp/certs/root-ca.crt"
      ssl_certificate_verification => true
      user => admin
      password => "xxxxxxxx"
    }
    stdout { codec => rubydebug }
 }
}

```

I tried to used logstash instead of cef-\* but I have the same result with geoip.ip filed and geoip.location field but the data of all row of index remaining without geoip. I'd like to improve this data with geo\_ip in order to use maps app of elastic....

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 16, 2019, 3:28pm UTC](https://discuss.elastic.co/t/geoip-doent-create-field-correctly/212012/2 "2019-12-16T15:28:42Z")

</div>

You will need an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html) that tells elasticsearch that [cef][destination][geoip][location] and [cef][source][geoip][location] should be of type geo\_point.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [December 16, 2019, 4:44pm UTC](https://discuss.elastic.co/t/geoip-doent-create-field-correctly/212012/3 "2019-12-16T16:44:10Z")

</div>

How could I set this in the dynamics template of logstash?

I tried to use this

```
  "logstash" : {
    "order" : 0,
    "version" : 60001,
    "index_patterns" : [
      "cef-*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "1",
        "refresh_interval" : "5s"
      }
    },
    "mappings" : {
      "dynamic_templates" : [
        {
          "message_field" : {
            "path_match" : "message",
            "mapping" : {
              "norms" : false,
              "type" : "text"
            },
            "match_mapping_type" : "string"
          }
        },
        {
          "string_fields" : {
            "mapping" : {
              "norms" : false,
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "ignore_above" : 256,
                  "type" : "keyword"
                }
              }
            },
            "match_mapping_type" : "string",
            "match" : "*"
          }
        }
      ],
      "properties" : {
        "@timestamp" : {
          "type" : "date"
        },
        "geoip" : {
          "dynamic" : true,
          "properties" : {
            "ip" : {
              "type" : "ip"
            },
            "latitude" : {
              "type" : "half_float"
            },
            "location" : {
              "type" : "geo_point"
            },
            "longitude" : {
              "type" : "half_float"
            }
          }
        },
        "@version" : {
          "type" : "keyword"
        }
      }
    },
    "aliases" : { }
  }

```

and I change the name in cef but I have the same problem. How could I re-use this template with fixing mapping on the field [cef][destination][geoip][location] and [cef][source][geoip][location]?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2020, 4:44pm UTC](https://discuss.elastic.co/t/geoip-doent-create-field-correctly/212012/4 "2020-01-13T16:44:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
