# How to use custom GeoIP2 database in elasticsearch?

**URL:** <https://discuss.elastic.co/t/how-to-use-custom-geoip2-database-in-elasticsearch/196507>\
**Category:** Elasticsearch\
**Created:** [August 23, 2019, 11:27am UTC](https://discuss.elastic.co/t/how-to-use-custom-geoip2-database-in-elasticsearch/196507 "2019-08-23T11:27:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![icamys](https://avatars.discourse-cdn.com/v4/letter/i/f1d935/32.png) [@icamys](https://discuss.elastic.co/u/icamys)\
**Post date:** [August 23, 2019, 11:27am UTC](https://discuss.elastic.co/t/how-to-use-custom-geoip2-database-in-elasticsearch/196507/1 "2019-08-23T11:27:20Z")

</div>

Hello!

I'm using dockerized elasticsearch7.3 on my local machine and I'm trying to use my `GeoIP2-City.mmdb` to add geoip info.

I've read the length and breadth of [the official geoip processor description](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/geoip-processor.html) and I still can't manage to create a processor with custom geoip library.

I'm sending HTTP PUT request to

```auto
http://{{ elasticsearch_host }}:{{ elasticsearch_port }}/_ingest/pipeline/geoip

```

with data:

```auto
{
  "description" : "Add geoip info",
  "processors" : [
    {
      "geoip" : {
        "field" : "ip",
        "target_field" : "geo",
        "database_file" : "GeoIP2-City.mmdb"
      }
    }
  ]
}

```

And getting the following error:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "parse_exception",
        "reason": "[database_file] database file [GeoIP2-City.mmdb] doesn't exist",
        "property_name": "database_file",
        "processor_type": "geoip"
      }
    ],
    "type": "parse_exception",
    "reason": "[database_file] database file [GeoIP2-City.mmdb] doesn't exist",
    "property_name": "database_file",
    "processor_type": "geoip"
  },
  "status": 400
}

```

However if I try to create pipeline with `database_file` field set to the name of any shipped libraries (ex. `GeoLite2-City.mmdb`), the pipeline is created successful.

What I've done until now:

1. Created Dockerfile for elasticsearch:

2. Starting elasticsearch as a service via docker-compose:

Any help is appreciated.

Thank you.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 26, 2019, 9:00am UTC](https://discuss.elastic.co/t/how-to-use-custom-geoip2-database-in-elasticsearch/196507/2 "2019-08-26T09:00:10Z")

</div>

Hey,

see this snippet from the geoip processor docs at [GeoIP Processor | Elasticsearch Guide [7.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/geoip-processor.html)

> The `geoip` processor can run with other GeoIP2 databases from Maxmind. The files must be copied into the `ingest-geoip` config directory, and the `database_file` option should be used to specify the filename of the custom database. Custom database files must be stored uncompressed. The `ingest-geoip` config directory is located at `$ES_CONFIG/ingest-geoip` .

It does not look as if the file has been copied into the config directory in your docker file.

---

<div class="post-metadata">

**Author:** ![icamys](https://avatars.discourse-cdn.com/v4/letter/i/f1d935/32.png) [@icamys](https://discuss.elastic.co/u/icamys)\
**Post date:** [August 27, 2019, 9:46am UTC](https://discuss.elastic.co/t/how-to-use-custom-geoip2-database-in-elasticsearch/196507/3 "2019-08-27T09:46:26Z")

</div>

Hi! Thanks for your response!

I don't know where the config directory is exactly located (the regular `/etc/elasticsearch` does not exist inside the elastcisearch container, the `$ES_CONFIG` is not set) that's why I've tried to copy the database inside the directories:

- /usr/share/elasticsearch/modules/ingest-geoip/
- /usr/share/elasticsearch/config/ingest-geoip/
- /usr/share/elasticsearch/config/
- /etc/elasticsearch/ingest-geoip/

None of those worked. Any ideas?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 28, 2019, 9:47am UTC](https://discuss.elastic.co/t/how-to-use-custom-geoip2-database-in-elasticsearch/196507/4 "2019-08-28T09:47:35Z")

</div>

`/usr/share/elasticsearch/config/ingest-geoip` sounds good to me. can you share your dockerfile in a gist in order to reproduce?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 9:47am UTC](https://discuss.elastic.co/t/how-to-use-custom-geoip2-database-in-elasticsearch/196507/5 "2019-09-25T09:47:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
