# GeoIP - Elasticsearch

**URL:** <https://discuss.elastic.co/t/geoip-elasticsearch/363035>\
**Category:** Elasticsearch\
**Created:** [July 12, 2024, 12:54pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035 "2024-07-12T12:54:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![DFIR\_Cap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfir_cap/32/131799_2.png) [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Post date:** [July 12, 2024, 12:54pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/1 "2024-07-12T12:54:05Z")

</div>

Hi: I have an Elasticsearch installed in Ubuntu. What are the proper steps to setup Geoip so that every time I ingest data it is enriched with geolocation data?

Thanks

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [July 12, 2024, 12:56pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/2 "2024-07-12T12:56:52Z")

</div>

Hi @DFIR_Cap , welcome to our community.

How are you ingesting you data? from query, logstash, beats...

---

<div class="post-metadata">

**Author:** ![DFIR\_Cap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfir_cap/32/131799_2.png) [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Post date:** [July 12, 2024, 12:57pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/3 "2024-07-12T12:57:43Z")

</div>

For now Logstash, but it will eventually be both logstash and beats.

---

<div class="post-metadata">

**Author:** ![DFIR\_Cap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfir_cap/32/131799_2.png) [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Post date:** [July 12, 2024, 1:41pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/4 "2024-07-12T13:41:42Z")

</div>

I notice there is no ingest pipeline

```auto
 curl -XGET http://localhost:9200/_ingest/pipeline/geoip?pretty
{ }

```

But there is the cluster setting for GEOIP Download. How do I create the pipeline? Or am I missing a step?

```auto
 curl -XGET http://localhost:9200/_cluster/settings?pretty
{
  "persistent" : {
    "ingest" : {
      "geoip" : {
        "downloader" : {
          "eager" : {
            "download" : "true"
          }
        }
      }
    }
  },

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 12, 2024, 1:49pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/5 "2024-07-12T13:49:39Z")

</div>

Where are you parsing your data?

Since you are using Logstash, are you parsing your data in logstash?

---

<div class="post-metadata">

**Author:** ![DFIR\_Cap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfir_cap/32/131799_2.png) [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Post date:** [July 12, 2024, 1:53pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/6 "2024-07-12T13:53:08Z")

</div>

My idea is the full ELK Stack. Elasticsearch, Logstash, Kibana, Filebeat. At the moment, I only have Logstash and Elasticsearch installed. I have been just testing some ingests using logstash directly to elasticsearch.

Yes, parsing in logstash.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 12, 2024, 2:00pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/7 "2024-07-12T14:00:15Z")

</div>

In logstash you can use the `geoip` filter to get geoip information from public ip address.

The documentation can be found [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-geoip.html).

You would need to have your ip field and use the filter this way:

```auto
	geoip {
		source => "source_ip_field"
		target => "destination_field"
	}

```

Keep in mind that for this to work without any issues in Elasticsearch and Kibana you will need a template for your index and to map the destination field correctly as geo point as explained in this [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html).

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [July 12, 2024, 2:08pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/8 "2024-07-12T14:08:36Z")

</div>

To illustrate, I just ran this example and got this response:

```auto
input {
  generator {
    message => "34.107.161.234"
    count => 1
  }
  stdin {}
}

filter {
  geoip {
    database => "/Users/alexsalgado/Desktop/elastic/observability/logstash/logstash-8.14.3/data/geoip_database_management/1720790685/GeoLite2-City.mmdb"
    source => "message"
    target => "source" # Change target to "source" or another valid option
  }
}

output {
  stdout {
    codec => rubydebug
  }
}

```

result

```auto

{
       "message" => "34.107.161.234",
      "@version" => "1",
         "event" => {
        "sequence" => 0,
        "original" => "34.107.161.234"
    },
    "@timestamp" => 2024-07-12T13:59:54.780095Z,
          "host" => {
        "name" => "alexs-MacBook-Pro.local"
    },
        "source" => {
          "ip" => "34.107.161.234",
        "mmdb" => {
            "dma_code" => 616
        },
         "geo" => {
                 "region_name" => "Missouri",
                    "location" => {
                "lat" => 39.1027,
                "lon" => -94.5778
            },
                   "city_name" => "Kansas City",
             "region_iso_code" => "US-MO",
                    "timezone" => "America/Chicago",
              "continent_code" => "NA",
                "country_name" => "United States",
                 "postal_code" => "64184",
            "country_iso_code" => "US"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![DFIR\_Cap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfir_cap/32/131799_2.png) [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Post date:** [July 12, 2024, 2:09pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/9 "2024-07-12T14:09:47Z")

</div>

nice ok. and if I am going to let Elastic do the parsing? How would I set geoip up?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 12, 2024, 2:18pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/10 "2024-07-12T14:18:13Z")

</div>

> [@DFIR\_Cap](#):
>
> and if I am going to let Elastic do the parsing? How would I set geoip up?

Unless you are using an Elastic Agent integration or Filebeat module, elasticsearch will not parse anything by default.

I would need to create an ingest pipeline in Elasticsearch, parse your data in it and then use the geoip processor to add geoip information.

For example, this [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html) explains a little more about ingest pipelines and this is the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/geoip-processor.html) about the geoip processor.

It is pretty similar to what you have in a Logstash pipeline, but it is executed in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![DFIR\_Cap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfir_cap/32/131799_2.png) [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Post date:** [July 12, 2024, 2:18pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035/11 "2024-07-12T14:18:55Z")

</div>

Thanks very much for the info.
