# Geoip plugin and private address

**URL:** <https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863>\
**Category:** Logstash\
**Created:** [March 28, 2018, 6:18am UTC](https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863 "2018-03-28T06:18:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rudok](https://avatars.discourse-cdn.com/v4/letter/r/f17d59/32.png) [@rudok](https://discuss.elastic.co/u/rudok)\
**Post date:** [March 28, 2018, 6:18am UTC](https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863/1 "2018-03-28T06:18:55Z")

</div>

Hi,

I have IP ( private range ) , lot and lat coordinates (country, city ... information).  
Is there any way to create geoip point field in message that Elasticsearch and Kibana both understand from these variables?

I tried some older manuals in forum, but not working for me in elasticsearch 6.2 stack.

Thx

Rudolf

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 28, 2018, 2:13pm UTC](https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863/2 "2018-03-28T14:13:33Z")

</div>

Try [this](https://discuss.elastic.co/t/create-custom-geoip-database-for-logstash-5-2/79473/14). If it does not work, show us what does not work.

---

<div class="post-metadata">

**Author:** ![rudok](https://avatars.discourse-cdn.com/v4/letter/r/f17d59/32.png) [@rudok](https://discuss.elastic.co/u/rudok)\
**Post date:** [March 28, 2018, 7:14pm UTC](https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863/3 "2018-03-28T19:14:09Z")

</div>

Hi,

I tried it before but when I tried visualize in coordinate map I received following error:

No Compatible Fields: The "testbeat-\*" index pattern does not contain any of the following field types: geo\_point

My config file:

input { stdin {} }

filter{  
translate {  
regex =\> true  
dictionary\_path =\> "./mutate/chemosvit-geo.yml"  
field =\> "message"  
}

```
    json {
        source => "translation"
    }

```

}

output {

elasticsearch {  
hosts =\> "esearch.chemosvit.sk:9200"  
manage\_template =\> false  
index =\> "testbeat-%{+YYYY.MM.dd}"  
document\_type =\> "doc"  
user =\> blabla  
password =\> blabla  
ssl =\> false  
ssl\_certificate\_verification =\> false  
cacert =\> "/etc/logstash/root-ca.pem"  
# truststore\_password =\> changeit  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 28, 2018, 7:18pm UTC](https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863/4 "2018-03-28T19:18:30Z")

</div>

Do you have a template for that index? If you are using the fieldname geoip you would need something like

```auto
{
  "settings": {
    "number_of_shards": 1
  },
  "mappings": {
    "doc": {
      "properties": {
        "geoip": {
          "type": "geo_point"
        }
      }
    }
  }
}    

```

---

<div class="post-metadata">

**Author:** ![rudok](https://avatars.discourse-cdn.com/v4/letter/r/f17d59/32.png) [@rudok](https://discuss.elastic.co/u/rudok)\
**Post date:** [March 28, 2018, 7:21pm UTC](https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863/5 "2018-03-28T19:21:27Z")

</div>

Don`t have  
I am going to study how to create it 😃

Thx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2018, 7:21pm UTC](https://discuss.elastic.co/t/geoip-plugin-and-private-address/125863/6 "2018-04-25T19:21:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
