# Geoip filter plugin dat extension and update

**URL:** <https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277>\
**Category:** Logstash\
**Created:** [May 12, 2020, 4:59pm UTC](https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277 "2020-05-12T16:59:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![YvorL](https://avatars.discourse-cdn.com/v4/letter/y/9fc348/32.png) [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Post date:** [May 12, 2020, 4:59pm UTC](https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277/1 "2020-05-12T16:59:01Z")

</div>

Hi,

I didn't have any recent (within a year) discussions on the above (most of them are unanswered). My questions are:

- Can I use the ".dat" extension instead of the ".mmdb" format?
- Is there any way to avoid restarting the Logstash process after updating the database file?

Thank you!  
YvorL

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2020, 11:14pm UTC](https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277/2 "2020-05-12T23:14:22Z")

</div>

> [@YvorL](#):
>
> Is there any way to avoid restarting the Logstash process after updating the database file?

No. The database is handled by the MaxMind library and they have [declined](https://github.com/maxmind/GeoIP2-java/issues/27) to add automatic reload after a database update.

---

<div class="post-metadata">

**Author:** ![YvorL](https://avatars.discourse-cdn.com/v4/letter/y/9fc348/32.png) [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Post date:** [May 12, 2020, 11:58pm UTC](https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277/3 "2020-05-12T23:58:11Z")

</div>

Thank you! Any ideas for the ".dat" extension?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2020, 12:36am UTC](https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277/4 "2020-05-13T00:36:56Z")

</div>

Again, for logstash this is just a pass-through to MaxMind. If their library can handle .dat then it will work, if not, it will not. It is not a logstash question, it is a MaxMind question.

---

<div class="post-metadata">

**Author:** ![YvorL](https://avatars.discourse-cdn.com/v4/letter/y/9fc348/32.png) [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Post date:** [May 13, 2020, 9:46am UTC](https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277/5 "2020-05-13T09:46:23Z")

</div>

The plugin is a Logstash plugin installed with the application having official documentation. Users don't really care how it's solved under the hood. It's fine if you don't know the answer for the question, as I mentioned before, those who asked this before, didn't got any answer either.  
Also, the ".dat" format is the legacy GeoLite format so one would think it's supported. However, [it looks like](https://github.com/logstash-plugins/logstash-filter-geoip/issues/90) LS stopped supporting it and needs "mmdb" while -for example- Nginx supports that one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2020, 9:46am UTC](https://discuss.elastic.co/t/geoip-filter-plugin-dat-extension-and-update/232277/6 "2020-06-10T09:46:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
