# GEOIP Enable

**URL:** <https://discuss.elastic.co/t/geoip-enable/74116>\
**Category:** Logstash\
**Created:** [February 6, 2017, 8:14pm UTC](https://discuss.elastic.co/t/geoip-enable/74116 "2017-02-06T20:14:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 6, 2017, 8:14pm UTC](https://discuss.elastic.co/t/geoip-enable/74116/1 "2017-02-06T20:14:11Z")

</div>

Hi  
Firstly i am apologise for bugging the forum but it is just that i really want this to work. I have setup the stack using this link [https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-16-04](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-16-04)  
and it is work perfectly. Also they have another tutorial for Apache and Nginx geoip filter . But in my case i am clooecting logs from my dns instead of the web server.  
I already have the client ip , server ip , etc etc on my kibana but what i am still strugglling with is to convert that ip address to counttry code etc etc .. i do really appreciate if anyone has some kind if working exaample . I hopwe this make sense and really appreciate

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 7, 2017, 8:49am UTC](https://discuss.elastic.co/t/geoip-enable/74116/2 "2017-02-07T08:49:31Z")

</div>

Please show an example event. Have you tried using the geoip filter?

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 6:11am UTC](https://discuss.elastic.co/t/geoip-enable/74116/3 "2017-02-08T06:11:14Z")

</div>

No Magnus ....  
Here is what i have on my filter

geoip {  
source =\> "ip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}  
but nothing happen .. Logstash operate normally but coordinate no shown ... i am not sure this is correct or not.

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 6:18am UTC](https://discuss.elastic.co/t/geoip-enable/74116/4 "2017-02-08T06:18:34Z")

</div>

No Compatible Fields: The "packetbeat-\*" index pattern does not contain any of the following field types: geo\_point

this is the error when try to create tile map

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2017, 6:34am UTC](https://discuss.elastic.co/t/geoip-enable/74116/5 "2017-02-08T06:34:41Z")

</div>

> but nothing happen .. Logstash operate normally but coordinate no shown ... i am not sure this is correct or not.

Again, please show an example event. Either use a `stdout { codec => rubydebug }` output or copy/paste a JSON snippet from the JSON tab in Kibana.

> No Compatible Fields: The "packetbeat-\*" index pattern does not contain any of the following field types: geo\_point

And you've configured Logstash to store the events in packetbeat-\* indexes? What do the mappings for such an index look like? Use Elasticsearch's get mapping API to find out.

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 7:37am UTC](https://discuss.elastic.co/t/geoip-enable/74116/6 "2017-02-08T07:37:07Z")

</div>

transport:udp method:QUERY server: client\_ip:202.134.26.36 client\_port:40,251 client\_proc: status:OK bytes\_out:184 responsetime:0 query:class IN, type A, [www.google.com](http://www.google.com) count:1 ip:202.134.24.110 @timestamp:February 8th 2017, 20:26:19.184 type:dns direction:in bytes\_in:32 beat.hostname:ns2.kalianet.to [beat.name](http://beat.name):ns2.kalianet.to port:53 dns.additionals:{ "class": "IN", "data": "216.239.32.10", "name": "[ns1.google.com](http://ns1.google.com)", "ttl": 121534, "type": "A" }, { "class": "IN", "data": "216.239.34.10", "name": "[ns2.google.com](http://ns2.google.com)", "ttl": 121534, "type": "A" }, { "class": "IN", "data": "216.239.36.10", "name": "[ns3.google.com](http://ns3.google.com)", "ttl": 121534, "type": "A" }, { "class": "IN", "data": "216.239.38.10", "name": "[ns4.google.com](http://ns4.google.com)", "ttl": 121534, "type": "A" } dns.additionals\_count:4 dns.answers:{ "class": "IN", "data": "172.217.25.36", "name": "[www.google.com](http://www.google.com)", "ttl": 268, "type": "A" } dns.answers\_count:1 dns.authorities:{ "class": "IN", "data": "[ns3.google.com](http://ns3.google.com)", "name": "[google.com](http://google.com)", "ttl": 118299, "type": "NS" }, { "class": "IN", "data": "[ns4.google.com](http://ns4.google.com)", "name": "[google.com](http://google.com)", "ttl": 118299, "type": "NS" }, { "class": "IN", "data": "[ns1.google.com](http://ns1.google.com)", "name": "[google.com](http://google.com)", "ttl": 118299, "type": "NS" }, { "class": "IN", "data": "[ns2.google.com](http://ns2.google.com)", "name": "[google.com](http://google.com)", "ttl": 118299, "type": "NS" } dns.authorities\_count:4 dns.flags.authoritative:false dns.flags.recursion\_allowed:true dns.flags.recursion\_desired:true dns.flags.truncated\_response:false [dns.id:29](http://dns.id:29),482 dns.op\_code:QUERY dns.question.class:IN [dns.question.name](http://dns.question.name):www.google.com dns.question.type:A dns.response\_code:NOERROR resource:www.google.com client\_server: proc: @version:1 host:ns2.kalianet.to tags:beats\_input\_raw\_event \_id:AVocpq2K1VZH1ycwIW15 \_type:dns \_index:packetbeat-2017.02.08 \_score:

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 7:37am UTC](https://discuss.elastic.co/t/geoip-enable/74116/7 "2017-02-08T07:37:43Z")

</div>

is this what you meant ...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2017, 8:36am UTC](https://discuss.elastic.co/t/geoip-enable/74116/8 "2017-02-08T08:36:59Z")

</div>

> is this what you meant ...

No, but I think it's good enough in this case. It looks the geoip filter isn't able to look up 202.134.24.110. Is there anything about this in the logs? What happens if you use the default geoip database (i.e. comment out the `database` option)? With the default database I'm certainly able to look up the address:

```plaintext
$ cat test.config 
input { stdin { codec => plain } }
output { stdout { codec => rubydebug } }
filter {
  geoip {
    source => "message"
  }
}
$ echo 202.134.24.110 | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 8
Pipeline main started
{
       "message" => "202.134.24.110",
      "@version" => "1",
    "@timestamp" => "2017-02-08T08:36:23.215Z",
          "host" => "lnxolofon",
         "geoip" => {
                    "ip" => "202.134.24.110",
         "country_code2" => "TO",
         "country_code3" => "TON",
          "country_name" => "Tonga",
        "continent_code" => "OC",
              "latitude" => -20.0,
             "longitude" => -175.0,
              "timezone" => "Pacific/Tongatapu",
              "location" => [
            [0] -175.0,
            [1] -20.0
        ]
    }
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 8:43am UTC](https://discuss.elastic.co/t/geoip-enable/74116/9 "2017-02-08T08:43:45Z")

</div>

sorry magnus but i think i am not followed you .... i have remove the databases option. here is how it looks like now in my filter

geoip {  
source =\> "ip"  
target =\> "geoip"

# database =\> "/etc/logstash/GeoLiteCity.dat"

```
      add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
      add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
    }
    mutate {
      convert => ["[geoip][coordinates]", "float"]
    }

```

is it what you suggest ... should i add extra code etc etc

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2017, 8:46am UTC](https://discuss.elastic.co/t/geoip-enable/74116/10 "2017-02-08T08:46:41Z")

</div>

You should look in your Logstash log to see if there are clues about why the geoip filter is failing. Please also post all of your configuration. **Format it as preformatted text using the `</>` toolbar button.**

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 8:51am UTC](https://discuss.elastic.co/t/geoip-enable/74116/11 "2017-02-08T08:51:35Z")

</div>

input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
geoip {  
source =\> "ip"  
target =\> "geoip"

# database =\> "/etc/logstash/GeoLiteCity.dat"

```
      add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
      add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
    }
    mutate {
      convert => ["[geoip][coordinates]", "float"]
    }
date {
  match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
}

```

}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Here is my logstash config

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2017, 8:57am UTC](https://discuss.elastic.co/t/geoip-enable/74116/12 "2017-02-08T08:57:37Z")

</div>

I asked you to "format it as preformatted text using the \</\> toolbar button", yet you didn't. Why?

The problem is that you're only applying the geoip filter to events with the syslog type but your Packetbeat have another type.

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 9:13am UTC](https://discuss.elastic.co/t/geoip-enable/74116/13 "2017-02-08T09:13:38Z")

</div>

sorry magnus but maybe i am not following you ... apologise for my misunderstand .. please could you let me know how to format as you mention here

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2017, 9:15am UTC](https://discuss.elastic.co/t/geoip-enable/74116/14 "2017-02-08T09:15:42Z")

</div>

Don't you have a toolbar just above the text area where you're typing your text?

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 9:17am UTC](https://discuss.elastic.co/t/geoip-enable/74116/15 "2017-02-08T09:17:45Z")

</div>

i don't think so ... i am using the older version i guess as i could not install the latest version ... i think i am using kibana version 4

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2017, 9:19am UTC](https://discuss.elastic.co/t/geoip-enable/74116/16 "2017-02-08T09:19:29Z")

</div>

I am talking about [https://discuss.elastic.co](https://discuss.elastic.co) where you just typed a couple of sentences.

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 9:28am UTC](https://discuss.elastic.co/t/geoip-enable/74116/17 "2017-02-08T09:28:02Z")

</div>

sorry for the toolbar i did not get it you meant for my cut and paste here ...  
anyway ... any chance what can i do to find which type my packetbeat has ??

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2017, 9:32am UTC](https://discuss.elastic.co/t/geoip-enable/74116/18 "2017-02-08T09:32:54Z")

</div>

Just look at the event's `type` field in Kibana.

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 9:33am UTC](https://discuss.elastic.co/t/geoip-enable/74116/19 "2017-02-08T09:33:02Z")

</div>

sorry for that ... now i can see it ... how about the packetbeat evet type

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [February 8, 2017, 9:34am UTC](https://discuss.elastic.co/t/geoip-enable/74116/20 "2017-02-08T09:34:00Z")

</div>

it say dns ...

[Next page](https://discuss.elastic.co/t/geoip-enable/74116.md?page=2)
