# No location field Geoip plugin

**URL:** <https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644>\
**Category:** Logstash\
**Created:** [July 26, 2017, 12:57pm UTC](https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644 "2017-07-26T12:57:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![xiguazhi](https://avatars.discourse-cdn.com/v4/letter/x/db5fbb/32.png) [@xiguazhi](https://discuss.elastic.co/u/xiguazhi)\
**Post date:** [July 26, 2017, 12:57pm UTC](https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644/1 "2017-07-26T12:57:06Z")

</div>

After using Geoip plugin in a filter specifying the ip address field I am getting Location.lat and Location.lon fields but I am not getting a location field defined as geopoint, or anything for that matter

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/d/ad03fc8cfb4320f30d9f37b0606231652ca0e3dc.png)

I have installed the template for my index which is syslog-\*

curl -XPUT '10.10.6.60:9200/\_template/template\_1?pretty' -H 'Content-Type: application/json' -d'  
{  
"template" : "syslog-_",  
"version" : 50001,  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"default" : {  
"\_all" : {"enabled" : true, "norms" : false},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"path\_match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text",  
"norms" : false  
}  
}  
}, {  
"string\_fields" : {  
"match" : "_",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text", "norms" : false,  
"fields" : {  
"keyword" : { "type": "keyword", "ignore\_above": 256 }  
}  
}  
}  
} ],  
"properties" : {  
"@timestamp": { "type": "date", "include\_in\_all": false },  
"@version": { "type": "keyword", "include\_in\_all": false },  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "half\_float" },  
"longitude" : { "type" : "half\_float" }  
}  
},  
"location": {  
"type": "geo\_point"  
}  
}  
}  
}  
}  
'

and here is my conf

input{  
beats{  
port =\> 5044  
}  
tcp{  
port =\> 5151  
type =\> "zywall310"  
codec =\> cef  
}  
udp{  
port =\> 5151  
type =\> "zywall310"  
codec =\> cef  
}  
}  
filter{  
geoip {  
source =\> "sourceAddress"  
}  
}  
output{  
if [type] == "zywall310"  
{  
elasticsearch {  
hosts =\> ["10.10.6.60:9200"]  
index =\> "syslog-%{+YYYY.MM.dd}"  
}  
}  
else  
{  
elasticsearch {  
hosts =\> ["10.10.6.60:9200"]  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
}  
------------beats.conf------------------

filter{  
if [type] == "Zywall310" {  
grok {  
patterns\_dir =\> ["./patterns"]  
match =\> {  
"message" =\> "%{CISCOTIMESTAMP:timestamp}( %{SYSLOGHOST:sysloghost})? %{WORD:Program}: %{Zywallpri:Priority}|%{Make:make}|%{Model:model}|%{Version:version}|0|%{EventType}|5|src=%{IP:src\_ip} dst=%{IP:dst\_ip} spt=%{INT:src\_port} dpt=%{INT:dst\_port} msg=priority:%{Priority}, from %{Source} to %{Destination}, %{WORD:protocol}, service %{WORD:service}, %{Action}"  
}  
}  
}  
}  
^----------filter.conf----------------^

and my patterns file  
Zywallpri [0-9]  
Make \w+\b  
Model \w+\b\s\d{3}  
Version \d+(.\d{2}(\w+.\d))  
EventType \w+\s\w+  
Priority \d{1,3}  
Source \w+  
Destination \w+  
Action \w+

---------./patterns/Zywall.txt-----------

I'm fairly new to this and am setting it up in my homelab environment just trying to get a working model I can go with so patience is appreciated 🙂 . Any help would be great, thx!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2017, 8:14pm UTC](https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644/2 "2017-07-26T20:14:55Z")

</div>

Where are you defining the `sourceAddressc` field?

Also please use code formatting, the `</>` button, to make your posts easier to read 🙂

---

<div class="post-metadata">

**Author:** ![xiguazhi](https://avatars.discourse-cdn.com/v4/letter/x/db5fbb/32.png) [@xiguazhi](https://discuss.elastic.co/u/xiguazhi)\
**Post date:** [July 27, 2017, 3:52pm UTC](https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644/3 "2017-07-27T15:52:03Z")

</div>

There are 2 filters, one is in Beats.conf which is

```
filter{
geoip {
source => "sourceAddress"
}
```

---

<div class="post-metadata">

**Author:** ![xiguazhi](https://avatars.discourse-cdn.com/v4/letter/x/db5fbb/32.png) [@xiguazhi](https://discuss.elastic.co/u/xiguazhi)\
**Post date:** [July 27, 2017, 4:00pm UTC](https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644/4 "2017-07-27T16:00:05Z")

</div>

Unless I'm missunderstanding you? These are firewall logs, I've gotten everything, including applying the template and recreating the index, but geoip.location never gets created. I have geoip.location.lon and geoip.location.lat just not geoip. I've also ingested ASA logs and get similar results. Any help is appreciated again.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 28, 2017, 12:32am UTC](https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644/5 "2017-07-28T00:32:04Z")

</div>

I can see you are referring to that field, but unless I am missing something you aren't even creating that field (ie defining it) in your grok patterns, so it'll never be read.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2017, 12:32am UTC](https://discuss.elastic.co/t/no-location-field-geoip-plugin/94644/6 "2017-08-25T00:32:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
