# Logstash elasticsearch filter geoip fields nil

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-filter-geoip-fields-nil/75224>\
**Category:** Logstash\
**Created:** [February 15, 2017, 4:07pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-geoip-fields-nil/75224 "2017-02-15T16:07:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Len\_Rugen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/len_rugen/32/12801_2.png) [@Len\_Rugen](https://discuss.elastic.co/u/Len_Rugen)\
**Post date:** [February 15, 2017, 4:07pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-geoip-fields-nil/75224/1 "2017-02-15T16:07:55Z")

</div>

I'm trying to get some of the geoip fields from a prior event using this code:

```
          elasticsearch {
              hosts => ["myes:9200"]
              user => "elastic"
              password => "changeme"
              index => "exchange-*"
              query => "type:iis AND cs-user:%{[cs-user]}"
              fields => { "@timestamp" => "prior.timestamp"
                          "[geoip][location]" => "prior.location"
                          "[geoip][country_name]" => "prior.country_name"
                          "clientip" => "prior.clientip"
              } 
          }

```

I've also tried the format "geoip.location" =\> "prior.location", but both ways all geoip fields return nill. The prior timestamp and clientip seem to be be working correctly.

Any ideas?

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 16, 2017, 6:39am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-geoip-fields-nil/75224/2 "2017-02-16T06:39:56Z")

</div>

If you run the query directly does it return something?

---

<div class="post-metadata">

**Author:** ![Len\_Rugen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/len_rugen/32/12801_2.png) [@Len\_Rugen](https://discuss.elastic.co/u/Len_Rugen)\
**Post date:** [February 16, 2017, 2:09pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-geoip-fields-nil/75224/3 "2017-02-16T14:09:11Z")

</div>

Yes, looks like standard geoip section to me.

Frequently, the clientip of the current event will be the same as the prior.clientip. I've already ran the geoip filter on the current ip, so there should be good data in most of the prior events. I know some will have bad IP's, but this sample doesn't.

When I get this working, I'll skip this check if the ip's are the same 🙂

---

<div class="post-metadata">

**Author:** ![Len\_Rugen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/len_rugen/32/12801_2.png) [@Len\_Rugen](https://discuss.elastic.co/u/Len_Rugen)\
**Post date:** [February 16, 2017, 2:31pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-geoip-fields-nil/75224/4 "2017-02-16T14:31:44Z")

</div>

Even more interesting, I changed the fields to this:

```
              fields => { "@timestamp" => "[prior][timestamp]"
                          "geoip" => "[prior][geoip]"
                          "[geoip][location]" => "[prior][location]"
                          "[geoip][country_name]" => "[prior][country_name]"
                          "clientip" => "[prior][clientip]"
              } 

```

I get the entire geoip structure in prior.geoip, I just can't get the individual fields. It looks like I'm missing the syntax, but I don't know what to try.

```
  "@timestamp" => 2017-02-09T00:00:00.000Z,
        "s-ip" => "xxx6.1",
       "prior" => {
           "geoip" => {
              "timezone" => "America/Chicago",
                    "ip" => "xxxx.134",
              "latitude" => 38.9517,
        "continent_code" => "NA",
             "city_name" => "Columbia",
         "country_code2" => "US",
          "country_name" => "United States",
              "dma_code" => 604,
         "country_code3" => "US",
           "region_name" => "Missouri",
              "location" => [
            [0] -92.3341,
            [1] 38.9517
        ],
           "postal_code" => "65211",
             "longitude" => -92.3341,
           "region_code" => "MO"
    },
        "clientip" => "xxxxx134",
    "country_name" => nil,
        "location" => nil,
       "timestamp" => 2017-02-16T14:22:37.000Z
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2017, 2:32pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-geoip-fields-nil/75224/5 "2017-03-16T14:32:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
