# GEOIP woes

**URL:** <https://discuss.elastic.co/t/geoip-woes/165467>\
**Category:** Logstash\
**Created:** [January 23, 2019, 5:54pm UTC](https://discuss.elastic.co/t/geoip-woes/165467 "2019-01-23T17:54:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![nsutton](https://avatars.discourse-cdn.com/v4/letter/n/c2a13f/32.png) [@nsutton](https://discuss.elastic.co/u/nsutton)\
**Post date:** [January 23, 2019, 5:54pm UTC](https://discuss.elastic.co/t/geoip-woes/165467/1 "2019-01-23T17:54:16Z")

</div>

I've trawled through post after post about GEOIP to on avail. I think my problem might lie in a minimul understanding of mappings.

I have a fortigate firewall that is sending its logs via syslog to logstash. This all works great and GEOIP does find latitude and longitudes etc, but I can't for the life of me get it to store them as a geo\_point.

I've seen people say you need to change your mappings, but a new index is created each day. Do I need to change mappings every day? I'm guessing not.

Also, I didn't think you could change mappings when an index has been created. My indexes are created automatically when the data comes in. I tried a mutate filter but that idea fell flat on its face.

Here's a copy of my filter. I'm at the "throw my hands in the air whilst exclaiming 'it's bloody stupid'" point 🙂

```
filter {
    if [type] == "forti_log" {

        grok {
            match => ["message", "%{SYSLOG5424PRI:syslog_index}%{GREEDYDATA:message}"]
            overwrite => ["message"]
            tag_on_failure => ["forti_grok_failure"]
        }

        kv {
            source => "message"
            value_split => "="
            field_split => " "
        }

        mutate {
            add_field => { "temp_time" => "%{date} %{time}" }
            rename => { "type" => "ftg_type" }
            rename => { "subtype" => "ftg_subtype" }
            add_field => { "type" => "forti_log" }
            convert => { "rcvdbyte" => "integer" }
            convert => { "sentbyte" => "integer" }
        }

        date {
            match => ["temp_time", "yyyy-MM-dd HH:mm:ss"]
            timezone => "UTC"
            target => "@timestamp"
        }

        mutate {
            #add/remove fields as you see fit.
            remove_field => ["syslog_index","syslog5424_pri","path","temp_time","service","date","time","sentpkt","rcvdpkt","log_id","message","poluuid"]
        }
        
        geoip {
          source => "dstip"
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 23, 2019, 6:27pm UTC](https://discuss.elastic.co/t/geoip-woes/165467/2 "2019-01-23T18:27:33Z")

</div>

> [@nsutton](#):
>
> I've seen people say you need to change your mappings, but a new index is created each day. Do I need to change mappings every day?

You use an index template to do that. [This](https://discuss.elastic.co/t/location-dosent-convert-to-geo-point/131199/4) thread might help.

---

<div class="post-metadata">

**Author:** ![nsutton](https://avatars.discourse-cdn.com/v4/letter/n/c2a13f/32.png) [@nsutton](https://discuss.elastic.co/u/nsutton)\
**Post date:** [January 23, 2019, 7:22pm UTC](https://discuss.elastic.co/t/geoip-woes/165467/3 "2019-01-23T19:22:17Z")

</div>

Thank you for your reply Badger. That thread was very helpful. It led me to [this](https://www.elastic.co/blog/logstash_lesson_elasticsearch_mapping) article which really helped me understand how to create and modify a mapping, and apply it to multiple indexes.

Thanks agian!

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [January 24, 2019, 12:01am UTC](https://discuss.elastic.co/t/geoip-woes/165467/4 "2019-01-24T00:01:35Z")

</div>

The default logstash index template that is created when using the Elasticsearch output should already contain the proper mapping for geoip.location. If you're using a different output or clobbered the output template settings or modified the default template, then you may run into an issue, or if you've changed the target for the geoip filter (which it doesn't look like you have) to be a different field. You can confirm by getting the output of "GET \_template/logstash" in the Kibana dev console.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 24, 2019, 1:10am UTC](https://discuss.elastic.co/t/geoip-woes/165467/5 "2019-01-24T01:10:02Z")

</div>

I've been using geoip for years and never realized that -- the default index template ensures that the default target of the filter is a geo\_point. That's because I almost always have a src and a dst, so I never use the default target of the filter 😃 And if the field is not called geoip.location then the default template does not help.

It was a good idea, it just does not fit any use case I have ever seen.

---

<div class="post-metadata">

**Author:** ![nsutton](https://avatars.discourse-cdn.com/v4/letter/n/c2a13f/32.png) [@nsutton](https://discuss.elastic.co/u/nsutton)\
**Post date:** [January 24, 2019, 9:14am UTC](https://discuss.elastic.co/t/geoip-woes/165467/6 "2019-01-24T09:14:15Z")

</div>

I took a look at the logstash template and it did have a default geopoint mapping for geoip. The only departure from the norm in my setup was I was sending the data to an index called forti-YY-mm-dd. Could that have been why it wasn't using the logstash default template?

Either way, I'm up and running now geo detecting multiple fields into multiple targets 🙂

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [January 24, 2019, 2:52pm UTC](https://discuss.elastic.co/t/geoip-woes/165467/7 "2019-01-24T14:52:26Z")

</div>

> [@nsutton](#):
>
> The only departure from the norm in my setup was I was sending the data to an index called forti-YY-mm-dd. Could that have been why it wasn't using the logstash default template?

Precisely. The default template only matches "logstash-\*" index patterns. If you use a different index pattern then you'll need a new indexing template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2019, 2:52pm UTC](https://discuss.elastic.co/t/geoip-woes/165467/8 "2019-02-21T14:52:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
