i parsed syslog_message to extract ip address from my ADSL modem to check who's ringing and store it into a new text field Varx (of my logstash index). Varx is a IPV4 text value computed every hours by an update_by_query POST in a cron job. The query looks into the syslog_message string to set Varx. I developed the query in Kibana console and use the cUrl in a shell.
I would like later to use a service that fill geoip structure (using free maxmind DB) by using the IPv4 stored in Varx. Last step would be to display a MAP into kibana ?
My question is : I did not yet find a way to to that. Parsing all non empty VarX and set geoip.yyy to the appropriate value return by function(Varx).
Any accurate tips ? thanks for the help
Please note : i am completely new running ELK 5.6.4 on RPI3