# IP Field contained invalid IP address or hostname with geoip filter

**URL:** <https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803>\
**Category:** Logstash\
**Created:** [May 11, 2016, 4:19pm UTC](https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803 "2016-05-11T16:19:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Duleendra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duleendra/32/986_2.png) [@Duleendra](https://discuss.elastic.co/u/Duleendra)\
**Post date:** [May 11, 2016, 4:19pm UTC](https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803/1 "2016-05-11T16:19:11Z")

</div>

Hi

I am parsing a CSV file with the following configurations. This CSV file has a field which contains IP address.

Problem is , Logstash gives the following error with geoip for IP addresses even though IP addresses are valid.

**"IP Field contained invalid IP address or hostname"**

Did I miss anything in the configurations ?  
Can't I use the csv field directly in the geoip filter ?

```
input {
    file {
          path => "/Users/duleendra/Dev/ELK/logstash-2.3.2/data/*.csv"			
    }
}
filter {

  if [path] =~ "usage" {
    mutate { 
       replace => { "type" => "usage" } 
    }

csv {
    columns => ["oid","user_id","ip","package","source_type","doc_id","digital_type","publication","pub_date","unit_price","gst","total","payment","pay_ref","createon"]
    separator => ","
} 

geoip {
    source => "ip"
}

```

}

}

```
output {
    elasticsearch {
		hosts => ["localhost:9200"] 
	}
   
}

```

Thanks  
Duleendra

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 15, 2016, 11:35am UTC](https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803/2 "2016-05-15T11:35:01Z")

</div>

Well, what does the `ip` field contain?

---

<div class="post-metadata">

**Author:** ![Duleendra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duleendra/32/986_2.png) [@Duleendra](https://discuss.elastic.co/u/Duleendra)\
**Post date:** [May 15, 2016, 2:27pm UTC](https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803/3 "2016-05-15T14:27:21Z")

</div>

Hi Magnus

This ip field contains IP address and apparently those are valid.

If I tired the following , it works. But not sure any performance issues.

```
grok {
        match => { "message" => "%{IP:clientip}" }
   }

geoip {
    source => "clientip"

}

```

Is there a way to skip if the "ip" field contains any invalid IP address ?

Thanks  
Duleendra

---

<div class="post-metadata">

**Author:** ![jeraldsm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeraldsm/32/11005_2.png) [@jeraldsm](https://discuss.elastic.co/u/jeraldsm)\
**Post date:** [August 29, 2016, 8:53am UTC](https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803/4 "2016-08-29T08:53:46Z")

</div>

I am facing similar error: IP Field contained invalid IP address or hostname with geoip filter

`timestamp=>"2016-08-29T10:36:54.075000+0200", :message=>"IP Field contained invalid IP address or hostname", :field=>"client_ip", :event=>#<LogStash::Event:0x59fc3530 @metadata={}, @accessors=#<LogStash::Util::Accessors:0x3d081077 @store={"message"=>"^C82.103.128.63`

My logstash configuration:

> # Analyze geo location
> 
> ```
> if [client_ip] {
> geoip {
> source => "client_ip"
> target => "client_geoip"
> database => "/jsm/logstash/GeoLiteCity.dat"
> add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
> add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
> }
> mutate {
> convert => ["[geoip][coordinates]", "float"]
> }
> 
> ```

> ```
> if ("_grokparsefailure" in [tags]) {
> mutate {
> add_tag => ["geoip_parsefailure"]
> remove_tag => ["_grokparsefailure"]
> }
> }
> }
> 
> ```

PS: Client Ip contains IPorHost, default Logstash pattern.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 29, 2016, 11:46am UTC](https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803/5 "2016-08-29T11:46:09Z")

</div>

If `client_ip` _must_ be an IP address, perhaps you should to use the dns filter to look up hostnames and turn them into IP addresses? And if that's not successful and `client_ip` still contains a hostname, skip the geoip filter?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:41am UTC](https://discuss.elastic.co/t/ip-field-contained-invalid-ip-address-or-hostname-with-geoip-filter/49803/6 "2017-07-06T04:41:10Z")

</div>


