# Mapping ip address to geolocation

**URL:** <https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136>\
**Category:** Elasticsearch\
**Created:** [August 28, 2019, 2:30pm UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136 "2019-08-28T14:30:10Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![gr1sha](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gr1sha](https://discuss.elastic.co/u/gr1sha)\
**Post date:** [August 28, 2019, 2:30pm UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/1 "2019-08-28T14:30:11Z")

</div>

Hi there. I am trying to create a region map so that I can see the activity of users from different countries. I have an ip address field in my index and what I am trying to do is map it to geoip location to get fields like location, latitude , longitude and etc. I have a source feeding the data directly to elasticsearch from filebeat and I am running everything on elastic cloud. How do I map my ip address internally, I mean without touching filebeat or any files but within Kibana or elasticsearch so that I will get this field in my index? Thank you.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [August 28, 2019, 9:10pm UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/2 "2019-08-28T21:10:02Z")

</div>

Sounds like you need to send your data to Logstash first to do the geoip lookups and then ingest it into Elasticsearch. Geo-IP data is pulled from a database, which is not something Elasticsearch does as far as I know.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 29, 2019, 7:39am UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/3 "2019-08-29T07:39:05Z")

</div>

Elasticsearch also features a [geoip processor](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/geoip-processor.html) nowadays, there is no need to use logstash for that, unless you need to do further processing.

---

<div class="post-metadata">

**Author:** ![gr1sha](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gr1sha](https://discuss.elastic.co/u/gr1sha)\
**Post date:** [August 29, 2019, 8:45am UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/4 "2019-08-29T08:45:59Z")

</div>

Ok, great, thanks! Just to clarify on that article you gave link to: it will only give instance of 1 ip address if following the way described there. However, what I need is something similar to automated procession of these ips. Am I wrong or misunderstanding something?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 29, 2019, 9:26am UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/5 "2019-08-29T09:26:24Z")

</div>

I'm sorry, I am not sure I get the question. Can you elaborate what you mean with automated procession? What exactly are you trying to do?

---

<div class="post-metadata">

**Author:** ![gr1sha](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gr1sha](https://discuss.elastic.co/u/gr1sha)\
**Post date:** [August 29, 2019, 9:30am UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/6 "2019-08-29T09:30:06Z")

</div>

I am trying to map the field that contains ip addresses , although they are of the type "string", to geoip so that I will have a field (or fields) representing the geo location of these ip addresses in order to build map visualization.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 29, 2019, 10:27am UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/7 "2019-08-29T10:27:23Z")

</div>

yes, the geoip processor will create additional fields in the JSON document, that need to be mapped properly. You should use the [simulate pipeline API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/simulate-pipeline-api.html) to figure out the structure of your resulting JSON document and then map the fields properly in your index before doing any indexation.

---

<div class="post-metadata">

**Author:** ![gr1sha](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gr1sha](https://discuss.elastic.co/u/gr1sha)\
**Post date:** [August 29, 2019, 3:36pm UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/8 "2019-08-29T15:36:17Z")

</div>

How would I map ip field in my index to get new fields?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 30, 2019, 8:17am UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/9 "2019-08-30T08:17:48Z")

</div>

can you be more specific where your problem is? Take a look at index templates and the mapping datatypes, then try to create a proper template, and let's iterate from there if it is not working.

---

<div class="post-metadata">

**Author:** ![gr1sha](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gr1sha](https://discuss.elastic.co/u/gr1sha)\
**Post date:** [August 30, 2019, 10:32am UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/10 "2019-08-30T10:32:37Z")

</div>

Yes , sorry , I will be more specific. So, I have managed to do the simulation of pipelines and it works correctly, I get the geoip output with country, latitude, longitude and etc. Now, what I need is to actually create these geoip simulated fields in my already existing index. How should I approach this?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 30, 2019, 12:25pm UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/11 "2019-08-30T12:25:41Z")

</div>

you can use the [Put Mapping API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/indices-put-mapping.html) to update this in your index, if the fields have not been added yet.

---

<div class="post-metadata">

**Author:** ![gr1sha](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gr1sha](https://discuss.elastic.co/u/gr1sha)\
**Post date:** [August 30, 2019, 3:34pm UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/12 "2019-08-30T15:34:10Z")

</div>

How they would have been added if I did the pipeline simulation API? It is just an example of what I will get. Can you be more exact , in terms of updating the index, for example, following all the documentation that is what I get for simulated API:  
1)

PUT \_ingest/pipeline/~testing name~  
{  
"processors":[  
{  
"grok":  
{  
"field": "message",  
"patterns": ["~some pattern~"]  
}

```
  },
  {
    "geoip":{
      "field": "~name of appropriate field~"
    }
  }
  ]

```

}

1. 

POST \_ingest/pipeline/~testing name~/\_simulate  
{  
"docs": [  
{  
"\_source":{  
"message": "~relevant message~"  
}  
}  
]  
}

after executing these 2 commands, I get a geoip field which consists of continent,city and region name, country and region iso code , latitude and longitude.

Now , I have elasticsearch index and index pattern for it. I need to add these fields to index so that they will be updated and I will be able to see them in the index pattern.  
If you are saying that I should go with PUT Mapping API option then , if I am correct, by using PUT in dev tools it should work. This is how it should look like , I presume:

PUT /elasticsearch\_index/\_mappings/  
{  
"properties":{  
~name of all fields I have listed above and their types~  
}

The process above will add these fields to index, however , I don't think that any data will become visible ( by that I mean the fields that were created during pipeline simulation). Therefore, could you , please , write something similar to above to explain how can I save this pipeline to elasticsearch or whatever so that this template will treat all of these messages correctly and automatically do the mapping.  
In other words, I can create these fields but how to ship the data or map it from my ip field automatically.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 3:34pm UTC](https://discuss.elastic.co/t/mapping-ip-address-to-geolocation/197136/13 "2019-09-27T15:34:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
