# IP geolocation without Logstash

**URL:** https://discuss.elastic.co/t/ip-geolocation-without-logstash/18716
**Category:** Elasticsearch
**Created:** [July 17, 2014, 2:20pm UTC](https://discuss.elastic.co/t/ip-geolocation-without-logstash/18716 "2014-07-17T14:20:55Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Justin\_Koehler](https://avatars.discourse-cdn.com/v4/letter/j/838e76/32.png) [@Justin\_Koehler](https://discuss.elastic.co/u/Justin_Koehler)
#### Post date: [July 17, 2014, 2:20pm UTC](https://discuss.elastic.co/t/ip-geolocation-without-logstash/18716/1 "2014-07-17T14:20:55Z")

</div>

I'm working on a system to record usage data for an application that  
submits its data to an ES cluster. I would like to record the location of  
each data point based on IP geolocation. I found the Logstash plugin that  
uses the GeoIP databases, but I was unable to find any solutions built for  
just Elasticsearch. Has anybody done something like this before?

In addition, it would be convenient to extract the IP of the point itself  
from the "X-Forwarded-For" header of the incoming data point. Is there a  
way to access these headers when the point is received by Elasticsearch?

Thanks in advance for any help.

Justin

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e7cb0010-103c-4ff7-8cd7-f5da5188f9bc%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e7cb0010-103c-4ff7-8cd7-f5da5188f9bc%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![otisg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otisg/32/492_2.png) [@otisg](https://discuss.elastic.co/u/otisg)
#### Post date: [July 19, 2014, 4:26am UTC](https://discuss.elastic.co/t/ip-geolocation-without-logstash/18716/2 "2014-07-19T04:26:16Z")

</div>

Hi,

On Thursday, July 17, 2014 10:20:55 AM UTC-4, Justin Koehler wrote:

> I'm working on a system to record usage data for an application that  
> submits its data to an ES cluster. I would like to record the location of  
> each data point based on IP geolocation. I found the Logstash plugin that  
> uses the GeoIP databases, but I was unable to find any solutions built for  
> just Elasticsearch. Has anybody done something like this before?

This is something that's typically done outside ES, in a document  
processing pipeline or indexer.

In addition, it would be convenient to extract the IP of the point itself

> from the "X-Forwarded-For" header of the incoming data point. Is there a  
> way to access these headers when the point is received by Elasticsearch?

Doable with a custom Rest Action.

## Otis

Performance Monitoring \* Log Analytics \* Search Analytics  
Solr & Elasticsearch Support \* [http://sematext.com/](http://sematext.com/)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [August 4, 2014, 7:56am UTC](https://discuss.elastic.co/t/ip-geolocation-without-logstash/18716/3 "2014-08-04T07:56:48Z")

</div>

Hey,

this is exactly what logstash is for, so you may want to give it a try, as  
it is already there. 🙂  
Also you can use the geoip filter to extract the ip address from the header  
as well, granted you log that one.

--Alex

On Sat, Jul 19, 2014 at 6:26 AM, Otis Gospodnetic \<  
[otis.gospodnetic@gmail.com](mailto:otis.gospodnetic@gmail.com)\> wrote:

> Hi,
> 
> On Thursday, July 17, 2014 10:20:55 AM UTC-4, Justin Koehler wrote:
> 
> > I'm working on a system to record usage data for an application that  
> > submits its data to an ES cluster. I would like to record the location of  
> > each data point based on IP geolocation. I found the Logstash plugin that  
> > uses the GeoIP databases, but I was unable to find any solutions built for  
> > just Elasticsearch. Has anybody done something like this before?
> 
> This is something that's typically done outside ES, in a document  
> processing pipeline or indexer.
> 
> In addition, it would be convenient to extract the IP of the point itself
> 
> > from the "X-Forwarded-For" header of the incoming data point. Is there a  
> > way to access these headers when the point is received by Elasticsearch?
> 
> Doable with a custom Rest Action.
> 
> ## Otis
> 
> Performance Monitoring \* Log Analytics \* Search Analytics  
> Solr & Elasticsearch Support \* [http://sematext.com/](http://sematext.com/)
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGCwEM\_pMUstvq7dLJPhwY7iK5-TKm59tHsRk4ZHYutcUvzE0w%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGCwEM_pMUstvq7dLJPhwY7iK5-TKm59tHsRk4ZHYutcUvzE0w%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![Andreas\_Lehr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_lehr/32/1300_2.png) [@Andreas\_Lehr](https://discuss.elastic.co/u/Andreas_Lehr)
#### Post date: [September 5, 2014, 3:36pm UTC](https://discuss.elastic.co/t/ip-geolocation-without-logstash/18716/4 "2014-09-05T15:36:22Z")

</div>

Hi Alex,

how exactly could this work?  
For example we are using the pattern "Quotedstring" to extract the up to 4  
IPs in the X-Forwared-For header of our Apache Logs.  
When we then try using this one in the geoip filter the filter seems to  
miss the IP.

example:

grok {  
type =\> http\_log  
patterns\_dir =\> ["/opt/logstash/patterns"]  
pattern =\> "%{APACHELOG}"  
}  
geoip {  
source =\> "xforwardedfor\_header"  
fields =\> [ "city\_name", "country\_code2", "country\_name", "location",  
"real\_region\_name", "postal\_code" ]  
add\_tag =\> ["geoip"]  
}  
....  
patter excerpt:  
APACHELOG %{QUOTEDSTRING:xforwardedfor\_header} [%{HTTPDATE:time}]

Thanks!

Am Montag, 4. August 2014 09:56:53 UTC+2 schrieb Alexander Reelsen:

> Hey,
> 
> this is exactly what logstash is for, so you may want to give it a try, as  
> it is already there. 🙂  
> Also you can use the geoip filter to extract the ip address from the  
> header as well, granted you log that one.
> 
> --Alex
> 
> On Sat, Jul 19, 2014 at 6:26 AM, Otis Gospodnetic \<[otis.gos...@gmail.com](mailto:otis.gos...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > Hi,
> > 
> > On Thursday, July 17, 2014 10:20:55 AM UTC-4, Justin Koehler wrote:
> > 
> > > I'm working on a system to record usage data for an application that  
> > > submits its data to an ES cluster. I would like to record the location of  
> > > each data point based on IP geolocation. I found the Logstash plugin that  
> > > uses the GeoIP databases, but I was unable to find any solutions built for  
> > > just Elasticsearch. Has anybody done something like this before?
> > 
> > This is something that's typically done outside ES, in a document  
> > processing pipeline or indexer.
> > 
> > In addition, it would be convenient to extract the IP of the point itself
> > 
> > > from the "X-Forwarded-For" header of the incoming data point. Is there a  
> > > way to access these headers when the point is received by Elasticsearch?
> > 
> > Doable with a custom Rest Action.
> > 
> > ## Otis
> > 
> > Performance Monitoring \* Log Analytics \* Search Analytics  
> > Solr & Elasticsearch Support \* [http://sematext.com/](http://sematext.com/)
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/aa71ee2b-9894-4568-95f7-3be0e5b0738c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0d901d63-ee7b-4586-a8b6-60313ab16c85%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0d901d63-ee7b-4586-a8b6-60313ab16c85%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:04am UTC](https://discuss.elastic.co/t/ip-geolocation-without-logstash/18716/5 "2017-07-06T01:04:04Z")

</div>


