# Grok for IP then geoip and ip2proxy plugin?

**URL:** <https://discuss.elastic.co/t/grok-for-ip-then-geoip-and-ip2proxy-plugin/246362>\
**Category:** Logstash\
**Created:** [August 25, 2020, 10:34pm UTC](https://discuss.elastic.co/t/grok-for-ip-then-geoip-and-ip2proxy-plugin/246362 "2020-08-25T22:34:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mortimerj](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@mortimerj](https://discuss.elastic.co/u/mortimerj)\
**Post date:** [August 25, 2020, 10:34pm UTC](https://discuss.elastic.co/t/grok-for-ip-then-geoip-and-ip2proxy-plugin/246362/1 "2020-08-25T22:34:07Z")

</div>

Hello!

I'm trying to grok just the IP address from the field ClientIP, which can present as [1.2.3.4:4444] or 1.2.3.4:4444, then create a new field (clientipfixed), and apply the geoip and ip2proxy plugins to enrich it. I don't see clientipfixed getting created or enriched in my index after creation? I've included the config below thanks!

```auto
input {
file {
path => "/home/ubuntu/Desktop/test/*.csv"
sincedb_path => "/dev/null"
start_position => "beginning"
}
}
filter {
csv {
separator => ","
columns => ["CreationDate","UserIds","Operations","CreationTime","Id","Operation","OrganizationId","RecordType","ResultStatus","UserKey","UserType","Version","Workload","ClientIP","UserId","ClientIPAddress","ClientInfoString","ClientProcessName","ClientVersion","ExternalAccess","InternalLogonType","LogonType","LogonUserSid","MailboxGuid","MailboxOwnerSid","MailboxOwnerUPN","OrganizationName","OriginatingServer","SessionId","AffectedItems","CrossMailboxOperation","Folder","ObjectId","AzureActiveDirectoryEventType","ExtendedProperties","ModifiedProperties","Actor","ActorContextId","ActorIpAddress","InterSystemsId","IntraSystemId","SupportTicketId","Target","TargetContextId","ApplicationId","LogonError","AppId","Item","ClientAppId","DestFolder","CorrelationId","EventSource","ItemType","ListId","ListItemUniqueId","Site","UserAgent","WebId","SourceFileExtension","SiteUrl","SourceFileName","SourceRelativeUrl","CustomUniqueId","OperationProperties","DoNotDistributeEvent"]
}
grok{
match => { "ClientIP" => "%{IP:clientipfixed}" }
}
geoip{
source => "clientipfixed"
}
ip2proxy{
source => "clientipfixed"
database => "/home/ubuntu/Desktop/test/ip2proxydb"
}
}
output {
elasticsearch {
hosts => "http://localhost:9200"
index => "mappingtest"
}
stdout {}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 25, 2020, 11:17pm UTC](https://discuss.elastic.co/t/grok-for-ip-then-geoip-and-ip2proxy-plugin/246362/2 "2020-08-25T23:17:51Z")

</div>

What does [ClientIP] look like on stdout?

---

<div class="post-metadata">

**Author:** ![mortimerj](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@mortimerj](https://discuss.elastic.co/u/mortimerj)\
**Post date:** [August 26, 2020, 4:56pm UTC](https://discuss.elastic.co/t/grok-for-ip-then-geoip-and-ip2proxy-plugin/246362/3 "2020-08-26T16:56:18Z")

</div>

I'm seeing many errors in /var/log/logstash/logstash-plain.log that include the following, but I've sed'd all " out of the csv, and opened it to control-f check and make sure there aren't any "s.

`:exception=>#<CSV::MalformedCSVError: Unclosed quoted field on line 1.>}`

The resulting index and pattern have the following:

1. No field created for clientipfixed in index pattern
2. IPs like 1.1.1.1:1234 are indexed
3. IPs like [1.1.1.1]:1234 are not indexed
4. IPs that don't have port are indexed and enriched

---

<div class="post-metadata">

**Author:** ![mortimerj](https://avatars.discourse-cdn.com/v4/letter/m/13edae/32.png) [@mortimerj](https://discuss.elastic.co/u/mortimerj)\
**Post date:** [August 26, 2020, 5:25pm UTC](https://discuss.elastic.co/t/grok-for-ip-then-geoip-and-ip2proxy-plugin/246362/4 "2020-08-26T17:25:20Z")

</div>

I changed

`match => { "ClientIP" => "%{IP:clientipfixed}" }`

to

`match => { "message" => "%{IP:clientipfixed}" }`

and it worked... 🤦‍♂️

Sorry for dumb question!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2020, 5:25pm UTC](https://discuss.elastic.co/t/grok-for-ip-then-geoip-and-ip2proxy-plugin/246362/5 "2020-09-23T17:25:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
