# Logstash Private IP Address - geoip

**URL:** <https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989>\
**Category:** Logstash\
**Created:** [February 22, 2017, 7:21am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989 "2017-02-22T07:21:08Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bondo](https://avatars.discourse-cdn.com/v4/letter/b/ad7895/32.png) [@Bondo](https://discuss.elastic.co/u/Bondo)\
**Post date:** [February 22, 2017, 7:21am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/1 "2017-02-22T07:21:08Z")

</div>

I can successfully get geo-location data from my IIS weblogs into Elastic if it's a public IP, but there are some private IP addresses that I want to explicitly set to a certain geo-locations and it's not working quite right. Any thoughts?

```
input {
 file {
    #type => "iis"
    path => "C:/logs/*.log"
    start_position => "beginning" 
  }
}

filter {

  #ignore log comments
  if [message] =~ "^#" {
    drop {}
  }

  grok {
    # check that fields match your IIS log settings
    match => ["message", "%{TIMESTAMP_ISO8601:timestamp} %{NOTSPACE:s-sitename} %{IPORHOST:s-ip} %{WORD:cs-method} %{URIPATH:cs-uri-stem} %{NOTSPACE:cs-uri-query} %{NUMBER:s-port} %{NOTSPACE:cs-username} %{IPORHOST:c-ip} %{WORD:cs-version}"]
  }

  #Set the Event Timesteamp from the log
    date {
    match => ["log_timestamp", "YYYY-MM-dd HH:mm:ss"]
      timezone => "Etc/UTC"
  }	

  geoip {
    source => "c-ip"
    target => "geoip"
    add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
    add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]

    if [c-ip] =~ /^10\./ {
	    mutate { replace => { "[geoip][timezone]" => "Pacific/Auckland" } }
    mutate { replace => { "[geoip][country_name]" => "University of Otago" } }
    mutate { replace => { "[geoip][country_code2]" => "UO" } }
    mutate { replace => { "[geoip][country_code3]" => "UoO" } }
    mutate { remove_field => ["[geoip][location]" ] }
    mutate { add_field => { "[geoip][location]" => "170.525" } }
    mutate { add_field => { "[geoip][location]" => "-45.865" } }
    mutate { convert => ["[geoip][location]", "float" ] }
    mutate { replace => ["[geoip][latitude]", -45.856 ] }
    mutate { convert => ["[geoip][latitude]", "float" ] }
    mutate { replace => ["[geoip][longitude]", 170.525 ] }
    mutate { convert => ["[geoip][longitude]", "float" ] }
    }
  }

  mutate {
    convert => ["[geoip][coordinates]", "float" ]
  }	

  mutate {
    remove_field => ["log_timestamp"]
  }
}

# See documentation for different protocols:
# http://logstash.net/docs/1.4.2/outputs/elasticsearch
output {
  # stdout { codec => rubydebug }
    elasticsearch { hosts => ["localhost:9200"] }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2017, 8:35am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/2 "2017-02-22T08:35:53Z")

</div>

In what way is it not working quite right?

---

<div class="post-metadata">

**Author:** ![Bondo](https://avatars.discourse-cdn.com/v4/letter/b/ad7895/32.png) [@Bondo](https://discuss.elastic.co/u/Bondo)\
**Post date:** [February 22, 2017, 11:23am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/3 "2017-02-22T11:23:41Z")

</div>

Logstash errors with the below when I execute the config.

[2017-02-22T05:19:08,476][ERROR][logstash.agent] fetched an invalid config {:config=\>"input {\n file {\n #type =\> "iis"\n path =\> "C:/logs/\*.log"\n start\_position =\> "beginning" \n }\n}\n\nfilter {\n\n #ignore log comments\n if [message] =~ "^#" {\n drop {}\n }\n\n grok {\n # check that fields match your IIS log settings\n match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:s-sitename} %{IPORHOST:s-ip} %{WORD:cs-method} %{URIPATH:cs-uri-stem} %{NOTSPACE:cs-uri-query} %{NUMBER:s-port} %{NOTSPACE:cs-username} %{IPORHOST:c-ip} %{WORD:cs-version}"]\n }\n\n #Set the Event Timesteamp from the log\n date {\n match =\> ["log\_timestamp", "YYYY-MM-dd HH:mm:ss"]\n timezone =\> "Etc/UTC"\n }\t\n\n geoip {\n source =\> "c-ip"\n target =\> "geoip"\n add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]\n add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]\n\n if [c-ip] =~ /^10\./ {\n\t mutate { replace =\> { "[geoip][timezone]" =\> "Pacific/Auckland" } }\n mutate { replace =\> { "[geoip][country\_name]" =\> "University of Otago" } }\n mutate { replace =\> { "[geoip][country\_code2]" =\> "UO" } }\n mutate { replace =\> { "[geoip][country\_code3]" =\> "UoO" } }\n mutate { remove\_field =\> ["[geoip][location]" ] }\n mutate { add\_field =\> { "[geoip][location]" =\> "170.525" } }\n mutate { add\_field =\> { "[geoip][location]" =\> "-45.865" } }\n mutate { convert =\> ["[geoip][location]", "float" ] }\n mutate { replace =\> ["[geoip][latitude]", -45.856 ] }\n mutate { convert =\> ["[geoip][latitude]", "float" ] }\n mutate { replace =\> ["[geoip][longitude]", 170.525 ] }\n mutate { convert =\> ["[geoip][longitude]", "float" ] }\n }\n }\n\n mutate {\n convert =\> ["[geoip][coordinates]", "float" ]\n }\t\n\n mutate {\n remove\_field =\> ["log\_timestamp"]\n }\n}\n\n# See documentation for different protocols:\n# [http://logstash.net/docs/1.4.2/outputs/elasticsearch\noutput](http://logstash.net/docs/1.4.2/outputs/elasticsearch%5Cnoutput) {\n # stdout { codec =\> rubydebug }\n elasticsearch { hosts =\> ["localhost:9200"] }\n}\n", :reason=\>"Expected one of #, =\> at line 33, column 8 (byte 830) after filter {\n\n #ignore log comments\n if [message] =~ "^#" {\n drop {}\n }\n\n grok {\n # check that fields match your IIS log settings\n match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:s-sitename} %{IPORHOST:s-ip} %{WORD:cs-method} %{URIPATH:cs-uri-stem} %{NOTSPACE:cs-uri-query} %{NUMBER:s-port} %{NOTSPACE:cs-username} %{IPORHOST:c-ip} %{WORD:cs-version}"]\n }\n\n #Set the Event Timesteamp from the log\n date {\n match =\> ["log\_timestamp", "YYYY-MM-dd HH:mm:ss"]\n timezone =\> "Etc/UTC"\n }\t\n\n geoip {\n source =\> "c-ip"\n target =\> "geoip"\n add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]\n add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]\n\n if "}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2017, 12:15pm UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/4 "2017-02-22T12:15:11Z")

</div>

You're not closing your geoip filter.

---

<div class="post-metadata">

**Author:** ![Bondo](https://avatars.discourse-cdn.com/v4/letter/b/ad7895/32.png) [@Bondo](https://discuss.elastic.co/u/Bondo)\
**Post date:** [February 23, 2017, 3:21am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/5 "2017-02-23T03:21:20Z")

</div>

Where am I missing it? It looks like I have all the open/close in there.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 23, 2017, 4:36am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/6 "2017-02-23T04:36:08Z")

</div>

> [@Bondo](#):
>
> add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
> add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]

Don't do that, it's pointless. LS creates a geoip.location field for you.

> [@Bondo](#):
>
> # [Elasticsearch output plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.4.2/outputs/elasticsearch)

Are you really on 1.4?

---

<div class="post-metadata">

**Author:** ![Bondo](https://avatars.discourse-cdn.com/v4/letter/b/ad7895/32.png) [@Bondo](https://discuss.elastic.co/u/Bondo)\
**Post date:** [February 23, 2017, 5:25am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/7 "2017-02-23T05:25:49Z")

</div>

I'm using logstash 5.2.0.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 23, 2017, 6:34am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/8 "2017-02-23T06:34:58Z")

</div>

> Where am I missing it? It looks like I have all the open/close in there.

No. Your geoip filter looks like this:

```plaintext
  geoip {
    source => "c-ip"
    target => "geoip"
    add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
    add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]

```

The next line is the conditional and there's no closing brace in between.

---

<div class="post-metadata">

**Author:** ![Bondo](https://avatars.discourse-cdn.com/v4/letter/b/ad7895/32.png) [@Bondo](https://discuss.elastic.co/u/Bondo)\
**Post date:** [February 23, 2017, 8:26am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/9 "2017-02-23T08:26:24Z")

</div>

Ah thank you, looks to be working now!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2017, 8:26am UTC](https://discuss.elastic.co/t/logstash-private-ip-address-geoip/75989/10 "2017-03-23T08:26:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
