# How to use Filebeat pipelines for both source and dest GeoIP

**URL:** <https://discuss.elastic.co/t/how-to-use-filebeat-pipelines-for-both-source-and-dest-geoip/105891>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 31, 2017, 1:14pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-pipelines-for-both-source-and-dest-geoip/105891 "2017-10-31T13:14:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Clueless](https://avatars.discourse-cdn.com/v4/letter/c/35a633/32.png) [@Clueless](https://discuss.elastic.co/u/Clueless)\
**Post date:** [October 31, 2017, 1:14pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-pipelines-for-both-source-and-dest-geoip/105891/1 "2017-10-31T13:14:37Z")

</div>

I am ingesting network data, and trying to get both the destination and source IP address to populate as geoips. I am able to get one of them to work while using Filebeat pipeline, and elasticsearch's GeoIP plugin, but not both.

Below is a copy of the filebeat.yml with the pipeline section, and the elasticsearch pipelines.

filebeat.yml  
using GEOIP elastic search plugin  
output.eleasticsearch:  
hosts: [”x.x.x.x”]  
index: “fa-%{+yyyy-MM-dd}”  
template.enable: false  
pipelines:  
- pipeline: “DestIPGeo”  
- pipeline: “SrcIPGeo”

PUT \_ingest/pipeline/SrcIPGeo  
{  
“processors”: [  
“geoip”: {  
“field”: “SourceIP”,  
“target\_field” : “SrcGeoIP”  
}  
}  
]  
}

PUT \_ingest/pipeline/DestIPGeo  
{  
“processors”: [  
“geoip”: {  
“field”: “DestinationIP”,  
“target\_field” : “DestIPGeo”  
}  
}  
]

When I do this, only one of them works. I have tried doing just the src or just the dest, and they work, but not both pipelines enabled at the same time. Do I need to use logstash for this?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 1, 2017, 12:30pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-pipelines-for-both-source-and-dest-geoip/105891/2 "2017-11-01T12:30:06Z")

</div>

Filebeat will choose only one pipeline. The `pipelines` setting is used to select one pipeline based on configurable conditions or string formatters (e.g. if first string pipeline access non-present field, the next pipeline setting will be tested). You will have to put both lookups into one pipeline.

---

<div class="post-metadata">

**Author:** ![Clueless](https://avatars.discourse-cdn.com/v4/letter/c/35a633/32.png) [@Clueless](https://discuss.elastic.co/u/Clueless)\
**Post date:** [November 1, 2017, 1:20pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-pipelines-for-both-source-and-dest-geoip/105891/3 "2017-11-01T13:20:55Z")

</div>

Steffens,

I got it!

Thanks for the reply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2017, 1:21pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-pipelines-for-both-source-and-dest-geoip/105891/4 "2017-11-29T13:21:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
