# Geoip pipeline creation issue

**URL:** <https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348>\
**Category:** Elasticsearch\
**Created:** [February 28, 2019, 12:58pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348 "2019-02-28T12:58:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![derekmizak](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Post date:** [February 28, 2019, 12:58pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348/1 "2019-02-28T12:58:00Z")

</div>

I have created ingest pipeline as follow:

```
PUT _ingest/pipeline/geoip
{
  "description": "Add geoip info",
  "processors": [
    {
      
      "geoip": {
        "field": "dest.ip",
        "ignore_failure": true
      }
    }
  ]
}

```

Next I have indexed a single document:

```
POST packetbeat-dm-6.6.1-2019.02/doc/?pipeline=geoip
{
  "dest.ip":"80.34.121.50"
}

```

However, when I have requested this document,

```
GET packetbeat-dm-6.6.1-2019.02/_search
{
  "query": {
    "match": {
      "dest.ip":"80.34.121.50"
    }
  }
}

```

I couldnt see any of the processing done. What am I doing wrong here?

```
"hits" : [
      {
        "_index" : "packetbeat-dm-6.6.1-2019.02",
        "_type" : "doc",
        "_id" : "HgQnNGkB6DzpB6JS5TVw",
        "_score" : 8.552432,
        "_source" : {
          "dest.ip" : "80.34.121.50"
        }
      }
    ]
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 28, 2019, 2:03pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348/2 "2019-02-28T14:03:11Z")

</div>

I'm not able to reproduce the problem with:

```auto
POST _ingest/pipeline/_simulate
{
  "pipeline" :{
  "description": "date pipeline ",
  "processors": [
    {
      
      "geoip": {
        "field": "dest.ip",
        "ignore_failure": true
      }
    }
  ]},
  "docs": [
    {
      "_index": "index",
      "_type": "_doc",
      "_id": "id",
       "_source": {
          "dest": {
            "ip": "80.34.121.50"
          }
       }
    }
  ]
}

```

It gives:

```auto
{
  "docs" : [
    {
      "doc" : {
        "_index" : "index",
        "_type" : "_doc",
        "_id" : "id",
        "_source" : {
          "geoip" : {
            "continent_name" : "Europe",
            "region_iso_code" : "ES-M",
            "city_name" : "Pozuelo de Alarcón",
            "region_name" : "Madrid",
            "location" : {
              "lon" : -3.8134,
              "lat" : 40.4329
            },
            "country_iso_code" : "ES"
          },
          "dest" : {
            "ip" : "80.34.121.50"
          }
        },
        "_ingest" : {
          "timestamp" : "2019-02-28T14:02:29.878046Z"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![derekmizak](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Post date:** [February 28, 2019, 2:12pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348/3 "2019-02-28T14:12:54Z")

</div>

Hi, on \_simulate API it works for me as well - no issue. However not when I follow the steps in my post. Any idea what I should be looking at. What I have put in the post is almost 1:1 copy from the documentation. I would appreciate any suggestion

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 28, 2019, 2:16pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348/4 "2019-02-28T14:16:05Z")

</div>

That's because your document is:

```auto
{
  "dest.ip":"80.34.121.50"
}

```

Where mine is:

```auto
{
  "dest": {
    "ip":"80.34.121.50" 
  }
}

```

Not sure why this is not working though and if it is supposed to work with the dot notation.

---

<div class="post-metadata">

**Author:** ![derekmizak](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Post date:** [February 28, 2019, 2:19pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348/5 "2019-02-28T14:19:38Z")

</div>

Hey - bingo - dot notation is not working - once changed it is ok - thank you

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 28, 2019, 2:22pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348/6 "2019-02-28T14:22:14Z")

</div>

When you remove the `"ignore_failure": true`, then you are getting a proper message:

```auto
{
  "docs" : [
    {
      "error" : {
        "root_cause" : [
          {
            "type" : "exception",
            "reason" : "java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: field [dest] not present as part of path [dest.ip]",
            "header" : {
              "processor_type" : "geoip"
            }
          }
        ],
        "type" : "exception",
        "reason" : "java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: field [dest] not present as part of path [dest.ip]",
        "caused_by" : {
          "type" : "illegal_argument_exception",
          "reason" : "java.lang.IllegalArgumentException: field [dest] not present as part of path [dest.ip]",
          "caused_by" : {
            "type" : "illegal_argument_exception",
            "reason" : "field [dest] not present as part of path [dest.ip]"
          }
        },
        "header" : {
          "processor_type" : "geoip"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2019, 2:22pm UTC](https://discuss.elastic.co/t/geoip-pipeline-creation-issue/170348/7 "2019-03-28T14:22:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
