# How to fix \[logstash.filters.geoip.databasemanager\] Connection reset

**URL:** <https://discuss.elastic.co/t/how-to-fix-logstash-filters-geoip-databasemanager-connection-reset/294237>\
**Category:** Logstash\
**Created:** [January 13, 2022, 6:37am UTC](https://discuss.elastic.co/t/how-to-fix-logstash-filters-geoip-databasemanager-connection-reset/294237 "2022-01-13T06:37:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Frank\_Kuo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_kuo/32/90467_2.png) [@Frank\_Kuo](https://discuss.elastic.co/u/Frank_Kuo)\
**Post date:** [January 13, 2022, 6:37am UTC](https://discuss.elastic.co/t/how-to-fix-logstash-filters-geoip-databasemanager-connection-reset/294237/1 "2022-01-13T06:37:06Z")

</div>

hi guys,

I meet the issue and I don't know why? Does anybody know the reason?

```auto
Jan 14 10:23:18 OANWELKL1 logstash[4874]: [2022-01-14T10:23:18,644][WARN][org.logstash.instrument.metrics.gauge.LazyDelegatingGauge][main] A gauge metric of an unknown type (org.jruby.RubySymbol) has been
Jan 14 10:23:18 OANWELKL1 logstash[4874]: [2022-01-14T10:23:18,657][WARN][org.logstash.instrument.metrics.gauge.LazyDelegatingGauge] A gauge metric of an unknown type (org.jruby.RubySymbol) has been create
Jan 14 10:23:20 OANWELKL1 logstash[4874]: [2022-01-14T10:23:20,050][ERROR][logstash.filters.geoip.databasemanager] Connection reset {:cause=>java.net.SocketException: Connection reset}
Jan 14 10:23:20 OANWELKL1 logstash[4874]: [2022-01-14T10:23:20,121][INFO][logstash.filters.geoip][main] Using geoip database {:path=>"/var/lib/logstash/plugins/filters/geoip/CC/GeoLite2-City.mmdb"}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 14, 2022, 3:55am UTC](https://discuss.elastic.co/t/how-to-fix-logstash-filters-geoip-databasemanager-connection-reset/294237/2 "2022-01-14T03:55:46Z")

</div>

The geoip filter is based on a library from MaxMind. In 2021 they changed the licence on the API that Elastic uses to require that users keep their database up-to-date by downloading a new database from MaxMind every couple of weeks. Much more detail [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-geoip.html#plugins-filters-geoip-database_auto).

If you need to work in an air-gapped environment you can do the downloads from MaxMind yourself and update the databases that the filter uses. That is also explained in the documentation I linked to.

Note also that if you can find a CC-licensed DB rather than a EULA-licensed DB then the filter should be happy to use that (out-of-date) data forever.

I think the filter comes with a very old CC-licensed database (1.2.2 from 2017) so unless an online update has occurred an air-gapped install should work.

---

<div class="post-metadata">

**Author:** ![Frank\_Kuo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_kuo/32/90467_2.png) [@Frank\_Kuo](https://discuss.elastic.co/u/Frank_Kuo)\
**Post date:** [January 18, 2022, 7:03am UTC](https://discuss.elastic.co/t/how-to-fix-logstash-filters-geoip-databasemanager-connection-reset/294237/3 "2022-01-18T07:03:21Z")

</div>

Thanks Badger!! let me check!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2022, 7:03am UTC](https://discuss.elastic.co/t/how-to-fix-logstash-filters-geoip-databasemanager-connection-reset/294237/4 "2022-02-15T07:03:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
