# \_geoip\_lookup\_failure though all geoip fields are populated

**URL:** <https://discuss.elastic.co/t/geoip-lookup-failure-though-all-geoip-fields-are-populated/195267>\
**Category:** Logstash\
**Created:** [August 14, 2019, 8:55pm UTC](https://discuss.elastic.co/t/geoip-lookup-failure-though-all-geoip-fields-are-populated/195267 "2019-08-14T20:55:25Z")\
**Posts on this page:** 1\
**Showing post:** 12

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 15, 2019, 12:39am UTC](https://discuss.elastic.co/t/geoip-lookup-failure-though-all-geoip-fields-are-populated/195267/12 "2019-08-15T00:39:46Z")

</div>

Ow! I would argue that this is a bug. Most filters are a no-op if the source field does not exist. However, the geoip filter takes a different approach. If the field lookup fails then the java code [returns](https://github.com/logstash-plugins/logstash-filter-geoip/blob/eff8697992bab0873683ec6d3dd8e436b9e7a8ef/src/main/java/org/logstash/filters/GeoIPFilter.java#L114) false. The [ruby code](https://github.com/logstash-plugins/logstash-filter-geoip/blob/eff8697992bab0873683ec6d3dd8e436b9e7a8ef/lib/logstash/filters/geoip.rb#L109) either decorates the event or tags it for failure. There is no no-op path. I think the ruby code should duplicate the source existence check.

---

_[View the full topic](https://discuss.elastic.co/t/geoip-lookup-failure-though-all-geoip-fields-are-populated/195267)._
