# GeoIP issue on logstash conf file

**URL:** <https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031>\
**Category:** Logstash\
**Created:** [July 14, 2018, 2:17pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031 "2018-07-14T14:17:34Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdur\_Raqeeb1](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Abdur\_Raqeeb1](https://discuss.elastic.co/u/Abdur_Raqeeb1)\
**Post date:** [July 14, 2018, 2:17pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/1 "2018-07-14T14:17:35Z")

</div>

Hi,

Myself getting an error after giving an geoIP database separately for geoip city and geoIP country.

Please find the error message below

/usr/share/logstash/bin/logstash -t -f /etc/logstash/conf.d/beats.conf

WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
[WARN] 2018-07-14 14:10:04.888 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[FATAL] 2018-07-14 14:10:06.369 [LogStash::Runner] runner - The given configuration is invalid. Reason: Expected one of #, =\> at line 26, column 7 (byte 1207) after filter {  
grok {  
match =\> { "message" =\> '"remote address" %{IP:remote\_address} - "remote user" - ["local time" %{HTTPDATE:time}] "Request" "%{GREEDYDATA:request}" "status code" %{INT:http\_status\_code} "bytes Transfer" %{NOTSPACE:bytes-transfer} "http\_refere ""-" "http user agent" "%{DATA:httpuseragent}" "http x forwaded for" "%{DATA:http\_x\_forwarded\_for}""requesttime" "%{DATA:requesttime}" "upstream time" "%{DATA:upstream\_time}"'}  
match =\> { "message" =\> '%{IP:client\_ip} %{NOTSPACE:termination\_state} %{NOTSPACE:termination\_state} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{INT:http\_status\_code} %{NOTSPACE:bytes\_read} %{GREEDYDATA:http\_user\_agent}'}

add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]

}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]  
remove\_field =\> ["timestamp"]  
}

geoip {  
source =\> "client\_ip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-Country.mmdb" "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-City.mmdb"

[ERROR] 2018-07-14 14:10:06.387 [LogStash::Runner] Logstash - java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

Also please find my beats.conf file

input {  
beats {  
port =\> 5044  
}  
}

filter {  
grok {  
match =\> { "message" =\> '"remote address" %{IP:remote\_address} - "remote user" - ["local time" %{HTTPDATE:time}] "Request" "%{GREEDYDATA:request}" "status code" %{INT:http\_status\_code} "bytes Transfer" %{NOTSPACE:bytes-transfer} "http\_refere ""-" "http user agent" "%{DATA:httpuseragent}" "http x forwaded for" "%{DATA:http\_x\_forwarded\_for}""requesttime" "%{DATA:requesttime}" "upstream time" "%{DATA:upstream\_time}"'}  
match =\> { "message" =\> '%{IP:client\_ip} %{NOTSPACE:termination\_state} %{NOTSPACE:termination\_state} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{INT:http\_status\_code} %{NOTSPACE:bytes\_read} %{GREEDYDATA:http\_user\_agent}'}

add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]

}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]  
remove\_field =\> ["timestamp"]  
}

geoip {  
source =\> "client\_ip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-Country.mmdb" "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-City.mmdb"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}

}

output {  
elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
index =\> "filebeat"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2018, 6:09pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/2 "2018-07-14T18:09:05Z")

</div>

> database =\> "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-Country.mmdb" "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-City.mmdb"

I don't think the geoip filter supports more than one database. If it did the syntax would be this:

```
database => ["/etc/logstash/GeoLite2-Country_20180605/GeoLite2-Country.mmdb", "/etc/logstash/GeoLite2-Country_20180605/GeoLite2-City.mmdb"]

```

---

<div class="post-metadata">

**Author:** ![Abdur\_Raqeeb1](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Abdur\_Raqeeb1](https://discuss.elastic.co/u/Abdur_Raqeeb1)\
**Post date:** [July 15, 2018, 12:55pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/3 "2018-07-15T12:55:03Z")

</div>

> [@magnusbaeck](#):
>
> "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-City.mmdb"]

No its still getting an error

[ERROR] 2018-07-15 12:51:30.923 [LogStash::Runner] geoip - Invalid setting for geoip filter plugin:

filter {  
geoip {  
# This setting must be a path  
# Expected path (one value), got 2 values?  
database =\> ["/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-Country.mmdb", "/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-City.mmdb"]  
...  
}  
}  
[FATAL] 2018-07-15 12:51:30.942 [LogStash::Runner] runner - The given configuration is invalid. Reason: Something is wrong with your configuration.

If its not supporting the two geoip database,please let me know how can i get both country and city in dashboard.

This is my grok pattern  
match =\> { "message"=\> '%{IP:client\_ip} %{NOTSPACE:termination\_state} %{NOTSPACE:termination\_state} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{INT:http\_status\_code} %{NOTSPACE:bytes\_read} %{NOTSPACE:http\_referer} "%{NOTSPACE:http\_user\_agent}" "%{NOTSPACE:http\_x\_forwarded\_for}"request\_time=%{BASE10NUM:request\_time} upstream\_response\_time=%{BASE10NUM:upstream\_response\_time} body\_bytes\_sent=%{INT:body\_bytes\_sent} %{WORD:Country} %{WORD:Country\_Code} %{WORD:Region\_Name} %{WORD:City}'}

Please check and let me

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 15, 2018, 6:41pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/4 "2018-07-15T18:41:51Z")

</div>

Use two geoip filters, one for the country and one for the city?

---

<div class="post-metadata">

**Author:** ![Abdur\_Raqeeb1](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Abdur\_Raqeeb1](https://discuss.elastic.co/u/Abdur_Raqeeb1)\
**Post date:** [July 16, 2018, 12:56pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/5 "2018-07-16T12:56:12Z")

</div>

HI,

Thanks for the update.After adding an another filter for city my logstash patterns stopped getting worked ,its not segregating the logs.

While observing on logs found below error

[2018-07-16T12:53:28,523][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//127.0.0.1:9200](https://127.0.0.1:9200)"]}  
[2018-07-16T12:53:28,727][INFO][logstash.filters.geoip] Using geoip database {:path=\>"/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-Country.mmdb"}  
[2018-07-16T12:53:28,764][INFO][logstash.filters.geoip] Using geoip database {:path=\>"/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-City.mmdb"}  
[2018-07-16T12:53:29,390][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
[2018-07-16T12:53:29,457][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2f37ae53 run\>"}  
[2018-07-16T12:53:29,537][INFO][org.logstash.beats.Server] Starting server on port: 5044  
[2018-07-16T12:53:29,688][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>[]}

[2018-07-16T12:53:30,124][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-07-16T12:53:33,840][ERROR][logstash.pipeline] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {:pipeline\_id=\>"main", "exception"=\>"undefined method `tr' for 0.0:Float", "backtrace"=>["/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:344:in`convert\_float'", "org/jruby/RubyMethod.java:115:in `call'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyHash.java:1343:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:299:in`convert'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:252:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:145:in`do\_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:164:in `block in multi_filter'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filter_delegator.rb:44:in`multi\_filter'", "(eval):240:in `block in filter_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:443:in`filter\_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:422:in `worker_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:384:in`block in start\_workers'"], :thread=\>"#\<Thread:0x2f37ae53 sleep\>"}  
[2018-07-16T12:53:33,848][ERROR][logstash.pipeline] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {:pipeline\_id=\>"main", "exception"=\>"undefined method `tr' for 0.0:Float", "backtrace"=>["/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:344:in`convert\_float'", "org/jruby/RubyMethod.java:115:in `call'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyHash.java:1343:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:299:in`convert'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:252:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:145:in`do\_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:164:in `block in multi_filter'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filter_delegator.rb:44:in`multi\_filter'", "(eval):240:in `block in filter_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:443:in`filter\_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:422:in `worker_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:384:in`block in start\_workers'"], :thread=\>"#\<Thread:0x2f37ae53 sleep\>"}  
[2018-07-16T12:53:33,975][FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<NoMethodError: undefined method `tr' for 0.0:Float>, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:344:in`convert\_float'", "org/jruby/RubyMethod.java:115:in `call'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyHash.java:1343:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:299:in`convert'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:252:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:145:in`do\_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:164:in `block in multi_filter'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filter_delegator.rb:44:in`multi\_filter'", "(eval):240:in `block in filter_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:443:in`filter\_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:422:in `worker_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:384:in`block in start\_workers'"]}  
[2018-07-16T12:53:34,050][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

Check and suggest me the same

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 16, 2018, 6:29pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/6 "2018-07-16T18:29:30Z")

</div>

It looks like you're trying to convert a field that already contains a float value into a float value and that's apparently not supported.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2018, 6:41pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/7 "2018-07-16T18:41:47Z")

</div>

Are you using target =\> "geoip" in both filters?

---

<div class="post-metadata">

**Author:** ![Abdur\_Raqeeb1](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Abdur\_Raqeeb1](https://discuss.elastic.co/u/Abdur_Raqeeb1)\
**Post date:** [July 17, 2018, 7:48am UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/8 "2018-07-17T07:48:27Z")

</div>

This is how i have put my geo IP on beats.conf

```
  source => "client_ip"
  target => "geoip"
  database => ["/etc/logstash/GeoLite2-Country_20180605/GeoLite2-Country.mmdb"]
  add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
  add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
}
mutate {
  convert => ["[geoip][coordinates]", "float"]
}

```

geoip {  
source =\> "client\_ip"  
target =\> "geoip"  
database =\> ["/etc/logstash/GeoLite2-Country\_20180605/GeoLite2-City.mmdb"]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}

Please help to resolve this

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [July 17, 2018, 11:21am UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/9 "2018-07-17T11:21:56Z")

</div>

Why are you trying to use both the Country and City DBs? There is nothing in the Country DB that isn't in the City DB.

---

<div class="post-metadata">

**Author:** ![Abdur\_Raqeeb1](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Abdur\_Raqeeb1](https://discuss.elastic.co/u/Abdur_Raqeeb1)\
**Post date:** [July 17, 2018, 11:37am UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/10 "2018-07-17T11:37:43Z")

</div>

HI,

So if i use only city DB then it can show both city and Country in my elk dashboard ?

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [July 17, 2018, 11:38am UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/11 "2018-07-17T11:38:38Z")

</div>

Yes. As I said... "There is nothing in the Country DB that isn't in the City DB."

Try it for yourself and you will see.

---

<div class="post-metadata">

**Author:** ![Abdur\_Raqeeb1](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Abdur\_Raqeeb1](https://discuss.elastic.co/u/Abdur_Raqeeb1)\
**Post date:** [July 18, 2018, 3:38am UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/12 "2018-07-18T03:38:19Z")

</div>

Thanks ...Its works

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2018, 3:38am UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/140031/13 "2018-08-15T03:38:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
