# Geoip pipeline setting for Netflow (Map on Geo Location Dashboard)

**URL:** <https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454>\
**Category:** Kibana\
**Created:** [May 11, 2022, 10:45am UTC](https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454 "2022-05-11T10:45:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![IMagalashvili](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imagalashvili/32/105557_2.png) [@IMagalashvili](https://discuss.elastic.co/u/IMagalashvili)\
**Post date:** [May 11, 2022, 10:45am UTC](https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454/1 "2022-05-11T10:45:36Z")

</div>

Hi, we had added Netflow module to analyze traffic with Filebeat netflow module.  
Everything works but cant activate Map settings.  
As i found, we have to add new pipeline ( "geoip-info", for example) ad add "final\_pipeline": "geoip-info" for filebeat index template.  
Also we have desabled online mmdb files updates with "ingest.geoip.downloader.enabled" : false  
And update "database\_file" : "GeoLite2-City.mmdb".  
But nothing changed, the Map on Geo Location Dashboard still emty.

May be you have step-by-step manual or could provide more detailes how to activate Map on dashboard?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 11, 2022, 11:19am UTC](https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454/2 "2022-05-11T11:19:46Z")

</div>

Can you post how your geo data looks like?

---

<div class="post-metadata">

**Author:** ![IMagalashvili](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imagalashvili/32/105557_2.png) [@IMagalashvili](https://discuss.elastic.co/u/IMagalashvili)\
**Post date:** [May 11, 2022, 1:20pm UTC](https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454/3 "2022-05-11T13:20:21Z")

</div>

I mean **source.ip** and **destination.ip** fields from Netflow index.

 ![NF_1](https://us1.discourse-cdn.com/elastic/original/3X/7/0/70dbb2fb45498344655f1989bb1bee034df8b84b.png)

Example of fields (IPs are chamged)  
{  
"\_index": "filebeat-7.17.3-2022.05.10-000009",  
"\_type": "\_doc",  
"\_id": "fFsKsIABtoXZSYt0lLoJ",  
"\_version": 1,  
"\_score": 1,  
"\_source": {  
"@timestamp": "2022-05-10T22:15:23.000Z",  
"input": {  
"type": "netflow"  
},  
"ecs": {  
"version": "1.12.0"  
},  
"host": {  
"containerized": false,  
"ip": [  
"2.2.2.2",  
"fe80::250:56ff:fe8d:2fea",  
"192.168.122.1"  
],  
"mac": [  
"00:50:56:8d:2f:ea",  
"52:54:00:65:57:71",  
"52:54:00:65:57:71"  
],  
"hostname": "XX-YYY001",  
"architecture": "x86\_64",  
"os": {  
"codename": "Core",  
"type": "linux",  
"platform": "centos",  
"version": "7 (Core)",  
"family": "redhat",  
"name": "CentOS Linux",  
"kernel": "3.10.0-1160.42.2.el7.x86\_64"  
},  
"name": "XX-YYY001",  
"id": "bcde44628cbe47dba7570f0240e53be2"  
},  
"flow": {  
"id": "KjAIVzzSrEQ",  
"locality": "external"  
},  
"source": {  
"ip": "1.1.0.1",  
"locality": "external",  
"port": 443,  
"bytes": 28559,  
"packets": 57  
},  
"network": {  
"direction": "inbound",  
"community\_id": "1:2TP9g2WGvQftr/96Zu6Mu9BWVqs=",  
"transport": "tcp",  
"iana\_number": 6,  
"bytes": 28559,  
"packets": 57  
},  
"event": {  
"type": [  
"connection"  
],  
"start": "2022-05-10T22:12:52.786Z",  
"end": "2022-05-10T22:15:00.281Z",  
"duration": 127495000000,  
"created": "2022-05-10T22:15:23.352Z",  
"kind": "event",  
"category": [  
"network\_traffic",  
"network"  
],  
"action": "netflow\_flow"  
},  
"agent": {  
"name": "XX-YYY001",  
"type": "filebeat",  
"version": "7.17.3",  
"hostname": "XX-YYY001",  
"ephemeral\_id": "2b0392b6-80c6-421d-90db-b4a1df65e7ab",  
"id": "5f031d52-e349-4e82-a32d-1fedcc6ad4d0"  
},  
"observer": {  
"ip": "3.3.3.3"  
},  
"destination": {  
"locality": "external",  
"port": 51925,  
"ip": "1.1.1.1"  
},  
"related": {  
"ip": [  
"1.1.0.1",  
"1.1.1.1"  
]  
},  
"netflow": {  
"protocol\_identifier": 6,  
"forwarding\_status": 64,  
"bgp\_source\_as\_number": 0,  
"egress\_interface": 105,  
"destination\_ipv4\_prefix\_length": 28,  
"flow\_direction": 0,  
"bgp\_next\_hop\_ipv4\_address": "91.184.106.2",  
"exporter": {  
"source\_id": 2097,  
"version": 9,  
"timestamp": "2022-05-10T22:15:23.000Z",  
"uptime\_millis": 3914061309,  
"address": "3.3.3.3:19581"  
},  
"bgp\_destination\_as\_number": 0,  
"destination\_transport\_port": 51925,  
"destination\_ipv4\_address": "1.1.1.1",  
"flow\_start\_sys\_up\_time": 3913911095,  
"packet\_delta\_count": 57,  
"flow\_end\_sys\_up\_time": 3914038590,  
"source\_ipv4\_prefix\_length": 0,  
"tcp\_control\_bits": 24,  
"ip\_class\_of\_service": 0,  
"source\_transport\_port": 443,  
"type": "netflow\_flow",  
"octet\_delta\_count": 28559,  
"ingress\_interface": 73,  
"source\_ipv4\_address": "1.1.0.1"  
}  
},  
"fields": {  
"flow.id": [  
"KjAIVzzSrEQ"  
],  
"event.category": [  
"network\_traffic",  
"network"  
],  
"host.os.name.text": [  
"CentOS Linux"  
],  
"host.hostname": [  
"XX-YYY001"  
],  
"netflow.ip\_class\_of\_service": [  
0  
],  
"host.mac": [  
"00:50:56:8d:2f:ea",  
"52:54:00:65:57:71",  
"52:54:00:65:57:71"  
],  
"netflow.source\_transport\_port": [  
443  
],  
"netflow.tcp\_control\_bits": [  
24  
],  
"netflow.exporter.version": [  
9  
],  
"netflow.exporter.address": [  
"3.3.3.3:19581"  
],  
"host.os.version": [  
"7 (Core)"  
],  
"netflow.bgp\_source\_as\_number": [  
0  
],  
"host.os.name": [  
"CentOS Linux"  
],  
"netflow.destination\_ipv4\_prefix\_length": [  
28  
],  
"source.ip": [  
"1.1.0.1"  
],  
"agent.name": [  
"XX-YYY001"  
],  
"host.name": [  
"XX-YYY001"  
],  
"network.community\_id": [  
"1:2TP9g2WGvQftr/96Zu6Mu9BWVqs="  
],  
"event.kind": [  
"event"  
],  
"source.packets": [  
57  
],  
"host.os.type": [  
"linux"  
],  
"network.packets": [  
57  
],  
"netflow.flow\_start\_sys\_up\_time": [  
3913911095  
],  
"netflow.destination\_ipv4\_address": [  
"1.1.1.1"  
],  
"flow.locality": [  
"external"  
],  
"netflow.source\_ipv4\_prefix\_length": [  
0  
],  
"input.type": [  
"netflow"  
],  
"agent.hostname": [  
"XX-YYY001"  
],  
"host.architecture": [  
"x86\_64"  
],  
"agent.id": [  
"5f031d52-e349-4e82-a32d-1fedcc6ad4d0"  
],  
"source.port": [  
443  
],  
"ecs.version": [  
"1.12.0"  
],  
"host.containerized": [  
false  
],  
"event.created": [  
"2022-05-10T22:15:23.352Z"  
],  
"network.iana\_number": [  
"6"  
],  
"agent.version": [  
"7.17.3"  
],  
"host.os.family": [  
"redhat"  
],  
"event.start": [  
"2022-05-10T22:12:52.786Z"  
],  
"netflow.bgp\_next\_hop\_ipv4\_address": [  
"91.184.106.2"  
],  
"observer.ip": [  
"3.3.3.3"  
],  
"netflow.type": [  
"netflow\_flow"  
],  
"netflow.source\_ipv4\_address": [  
"1.1.0.1"  
],  
"destination.port": [  
51925  
],  
"netflow.flow\_end\_sys\_up\_time": [  
3914038590  
],  
"netflow.bgp\_destination\_as\_number": [  
0  
],  
"netflow.octet\_delta\_count": [  
28559  
],  
"event.end": [  
"2022-05-10T22:15:00.281Z"  
],  
"host.ip": [  
"2.2.2.2",  
"fe80::250:56ff:fe8d:2fea",  
"192.168.122.1"  
],  
"agent.type": [  
"filebeat"  
],  
"netflow.exporter.source\_id": [  
2097  
],  
"related.ip": [  
"1.1.0.1",  
"1.1.1.1"  
],  
"host.os.kernel": [  
"3.10.0-1160.42.2.el7.x86\_64"  
],  
"netflow.ingress\_interface": [  
73  
],  
"netflow.packet\_delta\_count": [  
57  
],  
"network.bytes": [  
28559  
],  
"network.direction": [  
"inbound"  
],  
"host.id": [  
"bcde44628cbe47dba7570f0240e53be2"  
],  
"netflow.exporter.uptime\_millis": [  
3914061309  
],  
"source.bytes": [  
28559  
],  
"netflow.flow\_direction": [  
0  
],  
"destination.locality": [  
"external"  
],  
"netflow.destination\_transport\_port": [  
51925  
],  
"netflow.exporter.timestamp": [  
"2022-05-10T22:15:23.000Z"  
],  
"host.os.codename": [  
"Core"  
],  
"destination.ip": [  
"1.1.1.1"  
],  
"source.locality": [  
"external"  
],  
"network.transport": [  
"tcp"  
],  
"event.duration": [  
127495000000  
],  
"netflow.protocol\_identifier": [  
6  
],  
"event.action": [  
"netflow\_flow"  
],  
"@timestamp": [  
"2022-05-10T22:15:23.000Z"  
],  
"host.os.platform": [  
"centos"  
],  
"event.type": [  
"connection"  
],  
"agent.ephemeral\_id": [  
"2b0392b6-80c6-421d-90db-b4a1df65e7ab"  
],  
"netflow.forwarding\_status": [  
64  
],  
"netflow.egress\_interface": [  
105  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 11, 2022, 1:45pm UTC](https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454/4 "2022-05-11T13:45:50Z")

</div>

You geoip processor hasn't set properly. Check documentation.

> **[GeoIP processor | Elasticsearch Guide \[8.2\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.2/geoip-processor.html#using-ingest-geoip)**

You must have a structure like this:

```auto
    "source.ip": "89.160.20.128",
    "geoip": {
      "continent_name": "Europe",
      "country_name": "Sweden",
      "country_iso_code": "SE",
      "city_name" : "Linköping",
      "region_iso_code" : "SE-E",
      "region_name" : "Östergötland County",
      "location": { "lat": 58.4167, "lon": 15.6167 }
    }

```

Also the mapping for source.ip/destination.ip support GeoJSON, for example:

```auto
"geoip" : {
  "dynamic": true,
  "properties" : {
    "ip": { "type": "ip" },
    "location" : { "type" : "geo_point" },
    "latitude" : { "type" : "half_float" },
    "longitude" : { "type" : "half_float" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![IMagalashvili](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imagalashvili/32/105557_2.png) [@IMagalashvili](https://discuss.elastic.co/u/IMagalashvili)\
**Post date:** [May 11, 2022, 2:30pm UTC](https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454/5 "2022-05-11T14:30:46Z")

</div>

> [@Rios](#):
>
> You geoip processor hasn't set properly. Check documentation.

Thank you! But I'm not familiar with elastic, so I need more detailed info/manual how to set up geoip processor properly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2022, 2:31pm UTC](https://discuss.elastic.co/t/geoip-pipeline-setting-for-netflow-map-on-geo-location-dashboard/304454/6 "2022-06-08T14:31:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
