# GeoIP filter - database file updated - restart required?

**URL:** <https://discuss.elastic.co/t/geoip-filter-database-file-updated-restart-required/155200>\
**Category:** Logstash\
**Created:** [November 2, 2018, 4:06pm UTC](https://discuss.elastic.co/t/geoip-filter-database-file-updated-restart-required/155200 "2018-11-02T16:06:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![YaoChim](https://avatars.discourse-cdn.com/v4/letter/y/8edcca/32.png) [@YaoChim](https://discuss.elastic.co/u/YaoChim)\
**Post date:** [November 2, 2018, 4:06pm UTC](https://discuss.elastic.co/t/geoip-filter-database-file-updated-restart-required/155200/1 "2018-11-02T16:06:01Z")

</div>

I have the following filter in Logstash 6.4.2

```
if [client_ip] !~ /^(10\.|172\.1[6-9]|172\.2[0-9]|172\.3[0-1]|192\.168|127\.)/ {
    geoip {
        database => "/opt/logstash/GeoLite2.mmdb"
        source => "client_ip"
    }
}

```

The above filter works fine.

My question - If I download and extract the updated GeoLite2.mmdb every month, do I need to restart Logstash everytime?

I can only find these other related topics:

- [Is restart required upon updating GeoIP database?](https://discuss.elastic.co/t/is-restart-required-upon-updating-geoip-database/90871)
- [Will logstash-filter-geoip automatically pickup new db file?](https://discuss.elastic.co/t/will-logstash-filter-geoip-automatically-pickup-new-db-file/24079)

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![YaoChim](https://avatars.discourse-cdn.com/v4/letter/y/8edcca/32.png) [@YaoChim](https://discuss.elastic.co/u/YaoChim)\
**Post date:** [November 6, 2018, 12:21pm UTC](https://discuss.elastic.co/t/geoip-filter-database-file-updated-restart-required/155200/2 "2018-11-06T12:21:41Z")

</div>

OK I've tested this my self and the answer is yes, you do have to restart Logstash after GeoIP database update.

When I overwrote the GeoIP.mmdb database with an updated version a whole load of errors was dumped out into the log file.

Logstash still processes the events and indexes them into ES but without any GeoIP information in the GeoIP fields.

A restart of Logstash and the GeoIP pipeline works as this obviously reloads the mmdb files.

Log Error example:  
[2018-11-06T12:14:46,992][ERROR][logstash.pipeline] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {:pipeline\_id=\>"main", "exception"=\>"a fault occurred in a recent unsafe memory access operation in compiled Java code", "backtrace"=\>["com.maxmind.db.Decoder.decodeByType(com/maxmind/db/Decoder.java:166)", "com.maxmind.db.Decoder.decode(com/maxmind/db/Decoder.java:147)", "com.maxmind.db.Decoder.decode(com/maxmind/db/Decoder.java:87)", "com.maxmind.db.Reader.resolveDataPointer(com/maxmind/db/Reader.java:252)", "com.maxmind.db.Reader.get(com/maxmind/db/Reader.java:150)", "com.maxmind.geoip2.DatabaseReader.get(com/maxmind/geoip2/DatabaseReader.java:151)", "com.maxmind.geoip2.DatabaseReader.country(com/maxmind/geoip2/DatabaseReader.java:196)", "org.logstash.filters.GeoIPFilter.retrieveCountryGeoData(org/logstash/filters/GeoIPFilter.java:306)", "org.logstash.filters.GeoIPFilter.handleEvent(org/logstash/filters/GeoIPFilter.java:148)", "java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:498)", "org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(org/jruby/javasupport/JavaMethod.java:453)", "org.jruby.javasupport.JavaMethod.invokeDirect(org/jruby/javasupport/JavaMethod.java:314)", "opt.logstash.vendor.bundle.jruby.$2\_dot\_3\_dot\_0.gems.logstash\_minus\_filter\_minus\_geoip\_minus\_5\_dot\_0\_dot\_3\_minus\_java.lib.logstash.filters.geoip.invokeOther2:handleEvent(opt/logstash/vendor/bundle/jruby/$2\_dot\_3\_dot\_0/gems/logstash\_minus\_filter\_minus\_geoip\_minus\_5\_dot\_0\_dot\_3\_minus\_java/lib/logstash/filters//opt/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-geoip-5.0.3-java/lib/logstash/filters/geoip.rb:111)", "opt.logstash.vendor.bundle.jruby.$2\_dot\_3\_dot\_0.gems.logstash\_minus\_filter\_minus\_geoip\_minus\_5\_dot\_0\_dot\_3\_minus\_java.lib.logstash.filters.geoip.filter(/opt/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-geoip-5.0.3-java/lib/logstash/filters/geoip.rb:111)", "opt.logstash.logstash\_minus\_core.lib.logstash.filters.base.invokeOther4:filter(opt/logstash/logstash\_minus\_core/lib/logstash/filters//opt/logstash/logstash-core/lib/logstash/filters/base.rb:143)", "opt.logstash.logstash\_minus\_core.lib.logstash.filters.base.do\_filter(/opt/logstash/logstash-core/lib/logstash/filters/base.rb:143)", "opt.logstash.logstash\_minus\_core.lib.logstash.filters.base.invokeOther4:do\_filter(opt/logstash/logstash\_minus\_core/lib/logstash/filters//opt/logstash/logstash-core/lib/logstash/filters/base.rb:162)", "opt.logstash.logstash\_minus\_core.lib.logstash.filters.base.block in multi\_filter(/opt/logstash/logstash-core/lib/logstash/filters/base.rb:162)", "org.jruby.RubyArray.each(org/jruby/RubyArray.java:1734)", "org.jruby.RubyArray$INVOKER$i$0$0$each.call(org/jruby/RubyArray$INVOKER$i$0$0$each.gen)", "opt.logstash.logstash\_minus\_core.lib.logstash.filters.base.invokeOther7:each(opt/logstash/logstash\_minus\_core/lib/logstash/filters//opt/logstash/logstash-core/lib/logstash/filters/base.rb:159)", "opt.logstash.logstash\_minus\_core.lib.logstash.filters.base.multi\_filter(/opt/logstash/logstash-core/lib/logstash/filters/base.rb:159)", "opt.logstash.logstash\_minus\_core.lib.logstash.filter\_delegator.invokeOther10:multi\_filter(opt/logstash/logstash\_minus\_core/lib/logstash//opt/logstash/logstash-core/lib/logstash/filter\_delegator.rb:44)", "opt.logstash.logstash\_minus\_core.lib.logstash.filter\_delegator.multi\_filter(/opt/logstash/logstash-core/lib/logstash/filter\_delegator.rb:44)", "RUBY.block in initialize((eval):66281)", "org.jruby.RubyArray.each(org/jruby/RubyArray.java:1734)", "org.jruby.RubyArray$INVOKER$i$0$0$each.call(org/jruby/RubyArray$INVOKER$i$0$0$each.gen)", "RUBY.block in initialize((eval):66278)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:289)", "org.jruby.RubyProc.call19(org/jruby/RubyProc.java:273)", "org.jruby.RubyProc$INVOKER$i$0$0$call19.call(org/jruby/RubyProc$INVOKER$i$0$0$call19.gen)", "RUBY.block in initialize((eval):66309)", "org.jruby.RubyArray.each(org/jruby/RubyArray.java:1734)", "org.jruby.RubyArray$INVOKER$i$0$0$each.call(org/jruby/RubyArray$INVOKER$i$0$0$each.gen)", "RUBY.block in initialize((eval):66306)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:289)", "org.jruby.RubyProc.call19(org/jruby/RubyProc.java:273)", "org.jruby.RubyProc$INVOKER$i$0$0$call19.call(org/jruby/RubyProc$INVOKER$i$0$0$call19.gen)", "RUBY.block in initialize((eval):66353)", "org.jruby.RubyArray.each(org/jruby/RubyArray.java:1734)", "org.jruby.RubyArray$INVOKER$i$0$0$each.call(org/jruby/RubyArray$INVOKER$i$0$0$each.gen)", "RUBY.block in initialize((eval):66337)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:289)", "org.jruby.RubyProc.call19(org/jruby/RubyProc.java:273)", "org.jruby.RubyProc$INVOKER$i$0$0$call19.call(org/jruby/RubyProc$INVOKER$i$0$0$call19.gen)", "RUBY.block in filter\_func((eval):7130)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:289)", "opt.logstash.logstash\_minus\_core.lib.logstash.pipeline.invokeOther3:filter\_func(opt/logstash/logstash\_minus\_core/lib/logstash//opt/logstash/logstash-core/lib/logstash/pipeline.rb:341)", "opt.logstash.logstash\_minus\_core.lib.logstash.pipeline.filter\_batch(/opt/logstash/logstash-core/lib/logstash/pipeline.rb:341)", "RUBY.worker\_loop(/opt/logstash/logstash-core/lib/logstash/pipeline.rb:320)", "RUBY.block in start\_workers(/opt/logstash/logstash-core/lib/logstash/pipeline.rb:286)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:289)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:246)", "java.lang.Thread.run(java/lang/Thread.java:748)"], :thread=\>"#\<Thread:0x4c47f548@/opt/logstash/logstash-core/lib/logstash/pipeline.rb:157 sleep\>"}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2018, 12:22pm UTC](https://discuss.elastic.co/t/geoip-filter-database-file-updated-restart-required/155200/3 "2018-12-04T12:22:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
