# Geoip process multiple fileds on ingest node

**URL:** <https://discuss.elastic.co/t/geoip-process-multiple-fileds-on-ingest-node/170214>\
**Category:** Elasticsearch\
**Created:** [February 27, 2019, 5:38pm UTC](https://discuss.elastic.co/t/geoip-process-multiple-fileds-on-ingest-node/170214 "2019-02-27T17:38:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![derekmizak](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Post date:** [February 27, 2019, 5:38pm UTC](https://discuss.elastic.co/t/geoip-process-multiple-fileds-on-ingest-node/170214/1 "2019-02-27T17:38:34Z")

</div>

Hi,

I would like to use geoip processor on the ingest node to process multiple fields, fr e.g.:

ip  
source.ip  
dest.ip

and any other IP related field which I may come across.

How can I create a pipeline which would utilize geoip ingest plugin to process multiple fields?

---

<div class="post-metadata">

**Author:** ![MikeKemmerer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikekemmerer/32/34385_2.png) [@MikeKemmerer](https://discuss.elastic.co/u/MikeKemmerer)\
**Post date:** [February 27, 2019, 5:51pm UTC](https://discuss.elastic.co/t/geoip-process-multiple-fileds-on-ingest-node/170214/2 "2019-02-27T17:51:44Z")

</div>

In order to accomplish this, you can simply have 3 consecutive geoip filters. Here's what we're doing with our normalized firewall and bro events:

```
if "fw" in [tags] or "bro" in [tags] {
    geoip {
        cache_size => 2000
        source => "DvcIp"
        target => "[GeoIPs][DvcIp]"
        fields => ["city_name", "country_code2", "country_code3", "country_name", "location", "postal_code", "region_code"]
    }
        geoip {
        cache_size => 2000
        source => "SrcIp"
        target => "[GeoIPs][SrcIp]"
        fields => ["city_name", "country_code2", "country_code3", "country_name", "location", "postal_code", "region_code"]
    }
    geoip {
        cache_size => 2000
        source => "DstIp"
        target => "[GeoIPs][DstIp]"
        fields => ["city_name", "country_code2", "country_code3", "country_name", "location", "postal_code", "region_code"]
    }
}
```

---

<div class="post-metadata">

**Author:** ![derekmizak](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Post date:** [February 27, 2019, 6:01pm UTC](https://discuss.elastic.co/t/geoip-process-multiple-fileds-on-ingest-node/170214/3 "2019-02-27T18:01:26Z")

</div>

Mike, Thank you for repsponse - looks like you are doing this on Logstash. I would like to do it on Ingest node but can get two geoip keys there - like this  
PUT \_ingest/pipeline/geoip-info  
{  
"description": "Add geoip info",  
"processors": [  
{

```
  "geoip": {
    "field": "ip",
    "target_field": "client.geo",
    "ignore_failure": true
  },
  "geoip": {
    "field": "source.ip",
    "target_field": "sourceip.geo",
    "ignore_failure": true
  }
}

```

]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 6:01pm UTC](https://discuss.elastic.co/t/geoip-process-multiple-fileds-on-ingest-node/170214/4 "2019-03-27T18:01:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
