# Longitude and latitude for logs

**URL:** <https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964>\
**Category:** Logstash\
**Created:** [August 25, 2016, 5:26pm UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964 "2016-08-25T17:26:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![anoopmk007](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@anoopmk007](https://discuss.elastic.co/u/anoopmk007)\
**Post date:** [August 25, 2016, 5:26pm UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964/1 "2016-08-25T17:26:22Z")

</div>

hello ,

My logs doesn't have any option to longitude and latitude information. Currently these client logs for one location copied to the server at same location and from there logstash sending to elsastcisearch server.

Similarly i have servers at each location.

Is there any way i can add longitude and latitude information from logstash ? so that in elastcisearch i can see the location information.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2016, 6:14pm UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964/2 "2016-08-25T18:14:20Z")

</div>

What would be the source of the geolocation information? The hostname of the Logstash machines, or what did you have in mind?

---

<div class="post-metadata">

**Author:** ![anoopmk007](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@anoopmk007](https://discuss.elastic.co/u/anoopmk007)\
**Post date:** [August 25, 2016, 6:19pm UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964/3 "2016-08-25T18:19:30Z")

</div>

Hi Magnus,

The host name of the logstash machine will be the geolocation.  
This server has internal ip 10._._.\*

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2016, 6:24pm UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964/4 "2016-08-25T18:24:55Z")

</div>

Have a look at the translate filter. It lets you define lookup table where Logstash looks up (in this case) the hostname or IP address and gets back a lat/lon pair.

---

<div class="post-metadata">

**Author:** ![anoopmk007](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@anoopmk007](https://discuss.elastic.co/u/anoopmk007)\
**Post date:** [August 25, 2016, 6:30pm UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964/5 "2016-08-25T18:30:54Z")

</div>

This is my logstash configuration.

input {  
file{  
path =\> "E:/DashBoard/OUTBOUND/\*"  
start\_position =\> "end"  
}  
}

filter  
{  
kv {  
source =\> "message"  
value\_split =\> "]"  
field\_split =\> ","  
trimkey =\> "["  
}  
}

output {  
elasticsearch { hosts =\> ["xx.xx.xx.xx:9200"] }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 25, 2016, 11:28pm UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964/6 "2016-08-25T23:28:11Z")

</div>

> [@anoopmk007](#):
>
> The host name of the logstash machine will be the geolocation. This server has internal ip 10...\*

You cannot use geolocation on this because the geoip filter only works on public IPs.

Have a look at [Creating geoip data for internal networks](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/), as @magnusbaeck mentioned.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:41am UTC](https://discuss.elastic.co/t/longitude-and-latitude-for-logs/58964/7 "2017-07-06T04:41:32Z")

</div>


