I've also tried the format "geoip.location" => "prior.location", but both ways all geoip fields return nill. The prior timestamp and clientip seem to be be working correctly.
Frequently, the clientip of the current event will be the same as the prior.clientip. I've already ran the geoip filter on the current ip, so there should be good data in most of the prior events. I know some will have bad IP's, but this sample doesn't.
When I get this working, I'll skip this check if the ip's are the same
I get the entire geoip structure in prior.geoip, I just can't get the individual fields. It looks like I'm missing the syntax, but I don't know what to try.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.