# Logstash and ip reputation

**URL:** <https://discuss.elastic.co/t/logstash-and-ip-reputation/24033>\
**Category:** Logstash\
**Created:** [June 20, 2015, 10:34am UTC](https://discuss.elastic.co/t/logstash-and-ip-reputation/24033 "2015-06-20T10:34:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![damstux](https://avatars.discourse-cdn.com/v4/letter/d/d26b3c/32.png) [@damstux](https://discuss.elastic.co/u/damstux)\
**Post date:** [June 20, 2015, 10:34am UTC](https://discuss.elastic.co/t/logstash-and-ip-reputation/24033/1 "2015-06-20T10:34:04Z")

</div>

Hello,

I have an ELK for my Apache Logs, everything OK.

I would like to query a reputation IP database to detect tor, vpn, open-proxy .... traffic on my website.

have you got any idea ?

I havec contacted [http://www.brightcloud.com/](http://www.brightcloud.com/) and [https://www.maxmind.com/](https://www.maxmind.com/) without success.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [June 20, 2015, 5:28pm UTC](https://discuss.elastic.co/t/logstash-and-ip-reputation/24033/2 "2015-06-20T17:28:33Z")

</div>

Only 2 things I can think of if it is not already in your data

You can have a file dictionary but I don't think that is what you want.  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html)

The other idea, is just write the ruby code to fetch the data you need  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html)

---

<div class="post-metadata">

**Author:** ![pemontto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pemontto/32/3908_2.png) [@pemontto](https://discuss.elastic.co/u/pemontto)\
**Post date:** [June 22, 2015, 11:08am UTC](https://discuss.elastic.co/t/logstash-and-ip-reputation/24033/3 "2015-06-22T11:08:49Z")

</div>

We currently do this using the [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter pointing to a YAML file structured like

```
<IP>: "<category>"

```

The dictionary, around 200k items, is loaded into memory on startup so it's quite performant. Alhough not ideal it works for our tactical solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:36am UTC](https://discuss.elastic.co/t/logstash-and-ip-reputation/24033/4 "2017-07-06T05:36:52Z")

</div>


