# Geoip filter

**URL:** <https://discuss.elastic.co/t/geoip-filter/253960>\
**Category:** Logstash\
**Created:** [November 1, 2020, 10:03pm UTC](https://discuss.elastic.co/t/geoip-filter/253960 "2020-11-01T22:03:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ronnie\_Raraihuru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie_raraihuru/32/48088_2.png) [@Ronnie\_Raraihuru](https://discuss.elastic.co/u/Ronnie_Raraihuru)\
**Post date:** [November 1, 2020, 10:03pm UTC](https://discuss.elastic.co/t/geoip-filter/253960/1 "2020-11-01T22:03:04Z")

</div>

**My sample log contents**

#Fields: date-time,connector-id,session-id,sequence-number,local-endpoint,remote-endpoint,event,data,context  
2020-10-22T23:59:53.533Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB78EDF,0,[127.0.0.1:25](http://127.0.0.1:25/),[127.0.0.1:10742](http://127.0.0.1:10742/),+,,  
2020-10-22T23:59:53.533Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB78EDF,1,[127.0.0.1:25](http://127.0.0.1:25/),[127.0.0.1:10742](http://127.0.0.1:10742/),\*,SMTPAcceptAnyRecipient,Set Session Permissions  
2020-10-22T23:59:53.533Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB78EDF,2,[127.0.0.1:25](http://127.0.0.1:25/),[127.0.0.1:10742](http://127.0.0.1:10742/),\>,"220 [SIG-EXCH13-01.sinpf.org.sb](http://sig-exch13-01.sinpf.org.sb/) Microsoft ESMTP MAIL Service

**My logstash pipeline**

input {  
beats {  
port =\> 5044  
}  
filter{  
mutate {  
gsub =\> ["message", ":" , ","]  
}  
csv{  
separator =\> ","  
columns =\> ["date", "hour", "minutes" , "connector-id","session-id","sequence-number","local-ip", "local-port", "remote-ip", "remote-port","event" ,"data","context"]

```
  }

```

geoip {  
source =\> "remote-ip"  
}

}

}

output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200/)"]  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}"

}  
}

My geoip filter is not working as expected, please help.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 2, 2020, 1:02am UTC](https://discuss.elastic.co/t/geoip-filter/253960/2 "2020-11-02T01:02:37Z")

</div>

What is not working?

The log lines examples that you shared only have private IPs, the geoip filter does not work with private IPs, only with public IPs.

---

<div class="post-metadata">

**Author:** ![Ronnie\_Raraihuru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie_raraihuru/32/48088_2.png) [@Ronnie\_Raraihuru](https://discuss.elastic.co/u/Ronnie_Raraihuru)\
**Post date:** [November 2, 2020, 2:27am UTC](https://discuss.elastic.co/t/geoip-filter/253960/3 "2020-11-02T02:27:13Z")

</div>

Thanks Leandro , it does but have not shared that . See below . Thanks

2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,3,192.168.1.110:25,60.169.126.177:3763,\<,EHLO ylmf-pc,  
2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,4,192.168.1.110:25,60.169.126.177:3763,\*,SMTPAcceptAnyRecipient,Set Session Permissions  
2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,5,192.168.1.110:25,60.169.126.177:3763,\>,250-SIG-EXCH13-01.sinpf.org.sb Hello [60.169.126.177],  
2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,6,192.168.1.110:25,60.169.126.177:3763,\>,250-SIZE 10485760,  
2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,7,192.168.1.110:25,60.169.126.177:3763,\>,250-PIPELINING,  
2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,8,192.168.1.110:25,60.169.126.177:3763,\>,250-DSN,  
2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,9,192.168.1.110:25,60.169.126.177:3763,\>,250-ENHANCEDSTATUSCODES,  
2020-10-23T21:13:32.471Z,SIG-EXCH13-01\Default Frontend SIG-EXCH13-01,08D8724E3CB79F0D,10,192.168.1.110:25,60.169.126.177:3763,\>,250-STARTTLS,

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 2, 2020, 3:01am UTC](https://discuss.elastic.co/t/geoip-filter/253960/4 "2020-11-02T03:01:46Z")

</div>

You didn't say what is not working, the configuration is correct.

```auto
geoip {
    source => "remote-ip"
}

```

This will apply the geoip filter on the public IPs in the field `remote-ip`.

You need to describe better what is the problem.

What is not working? What is the result that you expect to get and what is the result you are getting? Did you create the [mapping](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/geo-point.html) for the `geo_point` field?

Also, use the `<\>` code button when sharing configurations and log samples, it is better to read and replicate.

I've run your pipeline and the `geoip` filter worked without problem for this IP you shared.

```auto
 "geoip" => {
    "country_code3" => "CN",
    "region_name" => "Anhui",
    "longitude" => 117.2865,
    "country_name" => "China",
    "latitude" => 31.8642,
    "continent_code" => "AS",
     "timezone" => "Asia/Shanghai",
    "location" => {
        "lat" => 31.8642,
        "lon" => 117.2865
    },
    "country_code2" => "CN",
    "ip" => "60.169.126.177",
    "region_code" => "AH"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2020, 3:01am UTC](https://discuss.elastic.co/t/geoip-filter/253960/5 "2020-11-30T03:01:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
