# Geoip Issues with Logstash?

**URL:** <https://discuss.elastic.co/t/geoip-issues-with-logstash/28150>\
**Category:** Logstash\
**Created:** [August 27, 2015, 2:52am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150 "2015-08-27T02:52:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![killmasta93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/killmasta93/32/36022_2.png) [@killmasta93](https://discuss.elastic.co/u/killmasta93)\
**Post date:** [August 27, 2015, 2:52am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/1 "2015-08-27T02:52:42Z")

</div>

Hi I was wondering if someone could help me out. I have been at it a while but nothing and whats funny is that sometimes it shows the geoip of some countries but others not. Did i miss something?

[http://pastebin.com/pEPD6Y0T](http://pastebin.com/pEPD6Y0T)

Also when i run `tail -f /var/log/logstash/logstash.stdout`  
i should be getting something like this  
[http://s2.postimg.org/4vvn0yhbt/Clipboarder\_2015\_08\_26\_007.png](http://s2.postimg.org/4vvn0yhbt/Clipboarder_2015_08_26_007.png)

```
tags" => [
    [0] "PFSense",
    [1] "firewall",
    [2] "packetfilter",
    [3] "GeoIP"

```

but instead i get

[![](http://s9.postimg.org/7vxho0dxr/Clipboarder_2015_08_26_003.png) ](http://s9.postimg.org/7vxho0dxr/Clipboarder_2015_08_26_003.png)

```
tags" => [
 [0] "PFSense",
 [1] "firewall"

```

Thank you

[![](http://s9.postimg.org/ennwqv2xb/Clipboarder_2015_08_26_004.png) ](http://s9.postimg.org/ennwqv2xb/Clipboarder_2015_08_26_004.png)

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [August 27, 2015, 3:25am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/2 "2015-08-27T03:25:35Z")

</div>

The geoip filter won't work for private addresses, so everything in 10.0.0.0/8 (like all your block messages) won't get geo data added. The geoip filter only works on internet routable addresses.

---

<div class="post-metadata">

**Author:** ![killmasta93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/killmasta93/32/36022_2.png) [@killmasta93](https://discuss.elastic.co/u/killmasta93)\
**Post date:** [August 27, 2015, 3:50am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/3 "2015-08-27T03:50:28Z")

</div>

Hi,  
Thank you for your response, so the 10.141.5.1 is private? my network is 192.168.3.0/24

if that's correct then everything is working good? but i do see that some IP do not get registered with the country names

[![](http://s17.postimg.org/ebf9i35fz/Clipboarder_2015_08_26_010.png) ](http://s17.postimg.org/ebf9i35fz/Clipboarder_2015_08_26_010.png)

Thank you

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [August 27, 2015, 4:10am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/4 "2015-08-27T04:10:28Z")

</div>

That's right. Also, geoip lookup is a best effort, the database is definitely not thorough nor completely accurate, so you may find some IPs just do not resolve to anywhere. We also unfortunately ship and older version of the geoip database within Logstash, we will be shipping a newer version in a future release I believe.

---

<div class="post-metadata">

**Author:** ![lloydde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lloydde/32/4061_2.png) [@lloydde](https://discuss.elastic.co/u/lloydde)\
**Post date:** [August 27, 2015, 4:40am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/5 "2015-08-27T04:40:02Z")

</div>

> [@killmasta93](#):
>
> 10.141.5.1 is private? my network is 192.168.3.0/24

That's correct @killmasta93. These are called rfc1918 addresses, because that is the Requests for Comments (RFC) that defined them.

IPv4 Private Address Space and Filtering  
10.0.0.0/8 IP addresses: 10.0.0.0 -- 10.255.255.255.  
172.16.0.0/12 IP addresses: 172.16.0.0 -- 172.31.255.255.  
192.168.0.0/16 IP addresses: 192.168.0.0 – 192.168.255.255.

See also:

- [RFC 1918 - Address Allocation for Private Internets](http://tools.ietf.org/html/rfc1918)
- [Private network - Wikipedia](https://en.wikipedia.org/wiki/Private_network)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 27, 2015, 4:50am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/6 "2015-08-27T04:50:36Z")

</div>

You could try this [Creating geoip data for internal networks](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/3)

---

<div class="post-metadata">

**Author:** ![killmasta93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/killmasta93/32/36022_2.png) [@killmasta93](https://discuss.elastic.co/u/killmasta93)\
**Post date:** [August 27, 2015, 5:06pm UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/7 "2015-08-27T17:06:51Z")

</div>

Hi,  
@lloydde @Joshua_Rich thank you for helping me understand

and @warkolm i will sure check it out looks very interesting

Thank you again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:30am UTC](https://discuss.elastic.co/t/geoip-issues-with-logstash/28150/8 "2017-07-06T05:30:44Z")

</div>


