# Geolocation configuration in logstash

**URL:** <https://discuss.elastic.co/t/geolocation-configuration-in-logstash/261937>\
**Category:** Logstash\
**Created:** [January 22, 2021, 3:56pm UTC](https://discuss.elastic.co/t/geolocation-configuration-in-logstash/261937 "2021-01-22T15:56:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Falikou1](https://avatars.discourse-cdn.com/v4/letter/f/74df32/32.png) [@Falikou1](https://discuss.elastic.co/u/Falikou1)\
**Post date:** [January 22, 2021, 3:56pm UTC](https://discuss.elastic.co/t/geolocation-configuration-in-logstash/261937/1 "2021-01-22T15:56:33Z")

</div>

I configured my logstash to parse the logs.  
I now want to configure geolocation. Is there a unique configuration for geolocation?  
If so, I need help.  
Here is my logstash setup below. How to complete with the geolocation configuration?

input {  
tcp {  
port =\> "5141"  
codec =\> json  
type =\> "syslog"  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{SYSLOG5424PRI:syslog\_index}-\s\*%{SYSLOGHOST:syslog\_hostname} %{GREEDYDATA:syslog\_message}" }  
}  
json {  
source =\> "syslog\_message"  
}  
mutate {  
remove\_field =\> ["message", "syslog\_message"]  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\> ["[https://Elastic1:9200](https://Elastic1:9200)", "[https://Elastic2:9200](https://Elastic2:9200)"]  
user =\> "elastic"  
password =\> "xxxxxxx"  
cacert =\> "/etc/logstash/certs/ca.crt"  
index =\> "jstest-%{+YYYY.MM.dd}"  
action =\> "index"  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2021, 3:56pm UTC](https://discuss.elastic.co/t/geolocation-configuration-in-logstash/261937/2 "2021-02-19T15:56:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
