# GeoIP filter missing some ECS fields

**URL:** https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339
**Category:** Logstash
**Tags:** ecs-elastic-common-schema
**Created:** [May 12, 2023, 10:52pm UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339 "2023-05-12T22:52:05Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)
#### Post date: [May 12, 2023, 10:52pm UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/1 "2023-05-12T22:52:05Z")

</div>

I am using the GeoIP Logstash filter and it seems to not have some desired fields for example `[mmdb][isp]`. Overall it has no `as` or `mmdb` fields, as well as some other random fields. It does have all the `geo` fields however.

Any idea how to get these missing fields?

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [May 13, 2023, 1:02pm UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/2 "2023-05-13T13:02:05Z")

</div>

ECS doesn't have those fields. Try with `ecs_compatibility => "disabled"`

You can set it manually:

```auto
      mutate {
        add_field => { "[geo][mmdb][isp]" => "%{somevalue}" }
      }

```

---

<div class="post-metadata">

### Author: ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)
#### Post date: [May 15, 2023, 11:59pm UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/4 "2023-05-15T23:59:12Z")

</div>

Hi, where do I put the `ecs_compatibility => "disabled"` in the config? I added it in the code block appropriate to where I want it applied, but when I reload the Logstash service it causes a syntax error.

Edit: Nvm figured out it goes in the `geoip{}` block

---

<div class="post-metadata">

### Author: ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)
#### Post date: [May 16, 2023, 2:18am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/5 "2023-05-16T02:18:02Z")

</div>

One more question though. If I set it manually won't it not be from the MaxMind database? I want it to be from the MaxMind database, not set manually right?

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [May 16, 2023, 7:33am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/6 "2023-05-16T07:33:53Z")

</div>

Yes, put it inside the geoip plugin. Also is an option to put in logstash.yml or pipeline.yml as `pipeline.ecs_compatibility`.

```auto
 geoip {
       source => "[geo][ip]"
       ecs_compatibility => "disabled" # default is from logstash.yml or pipeline.yml
       #default_database_type => "City" # or ASN
       #database => "/etc/logstash/GeoLiteCity.dat"
       #tag_on_failure => ["IP lookup failed"]
   }

```

If MaxMind provide mmdb fileds no need to set, but that is not the ECS structure, so you need to avoid ECS, which you figure out how.  
You can also leave MaxMind to fill, then check if mmdb is missing/empty, add a value like default value.

---

<div class="post-metadata">

### Author: ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)
#### Post date: [May 17, 2023, 2:33am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/7 "2023-05-17T02:33:20Z")

</div>

Hi, I am currently running this:

```auto
mutate {
    add_field => {
        "[mmdb][isp]" => "%{somevalue}"
    }
}

```

because if I don't add the field the `mmdb.isp` isn't in Kibana at all. However once I add that mutate the `mmdb.isp` is there, but all the values are just `%{somevalue}`

Basically is it possible to actually have the real, correct values that are in the MaxMind database? What do you recommend?

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [May 17, 2023, 4:03am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/8 "2023-05-17T04:03:59Z")

</div>

If values exist in MaxMind should be visible with `ecs_compatibility => "disabled"`. If you set to always add\_field, the value will be overwritten. As I said, you can also leave geoip to fill MaxMind by the plugin, then check if mmdb is missing/empty, add a value like default value for all empty values.

Most likely free GeoLite2-City doesn't have it. The commercial version has more data. Test online [demo](https://www.maxmind.com/en/geoip-demo) for GeoIP2 City Plus Database and check info about [GeoIP2 ISP Database](https://www.maxmind.com/en/geoip2-isp-database).

> The GeoIP2 City database is a more accurate version of our free [GeoLite2 City](https://dev.maxmind.com/geoip/geolite2-free-geolocation-data) database.

> The default database is `GeoLite2-City` . This plugin supports several free databases (`GeoLite2-City` , `GeoLite2-Country` , `GeoLite2-ASN` ) and a selection of commercially-licensed databases (`GeoIP2-City` , `GeoIP2-ISP` , `GeoIP2-Country` ).

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [May 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/9 "2023-05-17T05:18:00Z")

</div>

One more thing, these are lookup values for 8.8.8.8 - Google DNS server. If is not in GeoLite2-City database, it's small chance to other ISP vales exist. So, there are option:  
a) manually add, it is not much geo locations, like company offices  
b) use commercial version GeoIP2

```auto
# ecs_compatibility => "disabled"

         "geoip" => {
           "region_name" => "California",
           "region_code" => "CA",
             "city_name" => "Los Angeles",
             "longitude" => -118.2441,
          "country_name" => "United States",
           "postal_code" => "90009",
              "latitude" => 34.0544,
                    "ip" => "8.8.8.8",
              "location" => {
            "lat" => 34.0544,
            "lon" => -118.2441
        },
        "continent_code" => "NA",
         "country_code2" => "US",
         "country_code3" => "US",
              "dma_code" => 803,
              "timezone" => "America/Los_Angeles"
    }

```

```auto
#ecs_compatibility => "v8"
         "geo" => {
                "country_name" => "United States",
                 "region_name" => "California",
                    "location" => {
                "lon" => -118.2441,
                "lat" => 34.0544
            },
                   "city_name" => "Los Angeles",
             "region_iso_code" => "US-CA",
                 "postal_code" => "90009",
              "continent_code" => "NA",
            "country_iso_code" => "US",
                    "timezone" => "America/Los_Angeles"
        }

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 14, 2023, 5:18am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339/10 "2023-06-14T05:18:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
