# Logstash: how to use multiple geoip filter in one message

**URL:** <https://discuss.elastic.co/t/logstash-how-to-use-multiple-geoip-filter-in-one-message/36248>\
**Category:** Logstash\
**Created:** [December 3, 2015, 7:08am UTC](https://discuss.elastic.co/t/logstash-how-to-use-multiple-geoip-filter-in-one-message/36248 "2015-12-03T07:08:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sumeet\_dembra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sumeet_dembra/32/56190_2.png) [@sumeet\_dembra](https://discuss.elastic.co/u/sumeet_dembra)\
**Post date:** [December 3, 2015, 7:08am UTC](https://discuss.elastic.co/t/logstash-how-to-use-multiple-geoip-filter-in-one-message/36248/1 "2015-12-03T07:08:46Z")

</div>

Hi,

I am using two geoip filters for one message. But the output shows geoip fields only for first geoip filter.

Here is the snippet for filters:

filter {  
grep {  
match =\> ["message","^#.\*"]  
negate =\> true  
}  
grok {  
match =\> ["message","%{LOGLINE}"]  
patterns\_dir=\>["/opt/mypatterns"]  
}  
geoip {  
source =\> "clientip"  
fields =\> ["country\_name", "city\_name", "continent\_code","country\_code2"]  
target =\> "client\_geoip"  
database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
}  
geoip {  
source =\> "ghostip"  
fields =\> ["country\_name", "city\_name", "continent\_code","country\_code2"]  
target =\> "ghost\_geoip"  
database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
}  
}

output {  
stdout { codec =\> rubydebug }  
}

The output shows geoip fields only for first geoip input .i.e. clientip and does not show geoip fields for second geoip input i.e. ghostip.

```
 "clientip" => "66.249.73.186",
 "ghostip" => "23.218.157.187",
 "client_geoip" => {
     "country_code2" => "US",
      "country_name" => "United States",
    "continent_code" => "NA",
         "city_name" => "Mountain View"
},
         "name" => "Other",
           "os" => "Other",
      "os_name" => "Other",
       "device" => "Other",

```

....

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 3, 2015, 7:19am UTC](https://discuss.elastic.co/t/logstash-how-to-use-multiple-geoip-filter-in-one-message/36248/2 "2015-12-03T07:19:48Z")

</div>

The grep filter is deprecated. Use conditionals instead.

If you comment out the first geoip filter I think you'll note that the second filter still isn't able to look up 23.218.157.187. Maybe the database is outdated?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:20am UTC](https://discuss.elastic.co/t/logstash-how-to-use-multiple-geoip-filter-in-one-message/36248/3 "2017-07-06T05:20:14Z")

</div>


