# Need help with adding geoip to syslog and then how to visualize... -

**URL:** <https://discuss.elastic.co/t/need-help-with-adding-geoip-to-syslog-and-then-how-to-visualize/209113>\
**Category:** Logstash\
**Created:** [November 22, 2019, 6:47pm UTC](https://discuss.elastic.co/t/need-help-with-adding-geoip-to-syslog-and-then-how-to-visualize/209113 "2019-11-22T18:47:25Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 25, 2019, 8:48pm UTC](https://discuss.elastic.co/t/need-help-with-adding-geoip-to-syslog-and-then-how-to-visualize/209113/11 "2019-11-25T20:48:41Z")

</div>

No, in the case of a private network, where you are adding the fields of geoip using mutate, you do not need to use a geoip filter.

To answer your previous post ... You need to use an index template. It could look very much like the [default template for logstash-\*](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json), which defines geoip.location as a geo\_point. Just change the index\_patterns field.

---

_[View the full topic](https://discuss.elastic.co/t/need-help-with-adding-geoip-to-syslog-and-then-how-to-visualize/209113)._
