# How to derive APM Source IP for Logstash Geoip

**URL:** <https://discuss.elastic.co/t/how-to-derive-apm-source-ip-for-logstash-geoip/181386>\
**Category:** APM\
**Tags:** server\
**Created:** [May 16, 2019, 11:54am UTC](https://discuss.elastic.co/t/how-to-derive-apm-source-ip-for-logstash-geoip/181386 "2019-05-16T11:54:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![digitalron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/digitalron/32/38224_2.png) [@digitalron](https://discuss.elastic.co/u/digitalron)\
**Post date:** [May 16, 2019, 11:54am UTC](https://discuss.elastic.co/t/how-to-derive-apm-source-ip-for-logstash-geoip/181386/1 "2019-05-16T11:54:49Z")

</div>

Elastic version: 7.0.1 (Docker)  
Elastic Components: Elasticsearch, Logstash, APM Server, Kibana

We have the geoip filter pipeline in Elastic, but decided to move it to Logstash to help share the load and reduce overhead on Elastic.

However, we are having problems deriving the source IP from a RUM request in Logstash. We have tried srcip, sourceip, clientip, client.ip and others but are failing miserably.

We're pretty sure it's something simple but are currently stumped and couldn't see any reference for it. Any help on this would be greatly appreciated.

TIA!

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [May 20, 2019, 3:40am UTC](https://discuss.elastic.co/t/how-to-derive-apm-source-ip-for-logstash-geoip/181386/2 "2019-05-20T03:40:41Z")

</div>

Hi again @digitalron, `client.ip` should be the right field. Does your configuration include something like this?

```auto
filter {
  geoip {
    source => "[client][ip]"
  }
}

```

If that doesn't get you on your way, please share your logstash configuration and steps to verify that it's failing. Also note if there is a [tag\_on\_failure](https://www.elastic.co/guide/en/logstash/current/plugins-filters-geoip.html#plugins-filters-geoip-tag_on_failure) present.

---

<div class="post-metadata">

**Author:** ![digitalron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/digitalron/32/38224_2.png) [@digitalron](https://discuss.elastic.co/u/digitalron)\
**Post date:** [May 20, 2019, 6:44am UTC](https://discuss.elastic.co/t/how-to-derive-apm-source-ip-for-logstash-geoip/181386/3 "2019-05-20T06:44:51Z")

</div>

Hi Gil, many thanks for that. That is indeed how we configured our logstash.conf and it is working now. After a lot of re-checks, we found out that we inadvertently got a non-printing whitespace character in between [client] and [ip] inserted on our reference file, causing the pipeline crash whenever we did a copy-paste from it. This can be closed now. Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2019, 2:49am UTC](https://discuss.elastic.co/t/how-to-derive-apm-source-ip-for-logstash-geoip/181386/4 "2019-06-10T02:49:10Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
