# Private IP GeoIP

**URL:** <https://discuss.elastic.co/t/private-ip-geoip/225927>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 31, 2020, 5:42pm UTC](https://discuss.elastic.co/t/private-ip-geoip/225927 "2020-03-31T17:42:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dshepard](https://avatars.discourse-cdn.com/v4/letter/d/fbc32d/32.png) [@dshepard](https://discuss.elastic.co/u/dshepard)\
**Post date:** [March 31, 2020, 5:42pm UTC](https://discuss.elastic.co/t/private-ip-geoip/225927/1 "2020-03-31T17:42:33Z")

</div>

Does anyone have a working config for assigning GeoIP data to private subnets wtih winlogbeat?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 1, 2020, 12:51am UTC](https://discuss.elastic.co/t/private-ip-geoip/225927/2 "2020-04-01T00:51:08Z")

</div>

[Creating geoip data for internal networks](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/14) is an older thread but will still work.

If you don't want to use Logstash you could use probably use an ingest pipeline to build something.

---

<div class="post-metadata">

**Author:** ![dshepard](https://avatars.discourse-cdn.com/v4/letter/d/fbc32d/32.png) [@dshepard](https://discuss.elastic.co/u/dshepard)\
**Post date:** [April 1, 2020, 1:22pm UTC](https://discuss.elastic.co/t/private-ip-geoip/225927/3 "2020-04-01T13:22:56Z")

</div>

I'm trying to use the instruction for beats 7.6.0.

[https://www.elastic.co/guide/en/siem/guide/7.6/conf-map-ui.html](https://www.elastic.co/guide/en/siem/guide/7.6/conf-map-ui.html)

But using that throws an error "Mapping values are not allowed in this context" I'm sure I'm just messing up the syntax.

I was wondering if anyone had an actual example of working code in Beats to add the GeoIP data.

I have a working config in Logstash using Translate, but since I have to rewrite that to match up to ECS, I figured I'd try the Elastic documented way. Frankly, I'm amazed that more people are demanding an easy way to add GeoIP data for private IPs.

---

<div class="post-metadata">

**Author:** ![Sam\_Chen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam_chen/32/67249_2.png) [@Sam\_Chen](https://discuss.elastic.co/u/Sam_Chen)\
**Post date:** [April 28, 2020, 6:46am UTC](https://discuss.elastic.co/t/private-ip-geoip/225927/4 "2020-04-28T06:46:19Z")

</div>

I have faced the same issue with filebeat cisco module that use default ingest pipeline,  
but it is too large and hard to maintenance.

Any best way to add for my own private IPs?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 7, 2020, 2:12pm UTC](https://discuss.elastic.co/t/private-ip-geoip/225927/5 "2020-05-07T14:12:06Z")

</div>

Using processors in Beats is a pretty simple solution if you don't have a lot of different locations or networks to map. Here's an example that I tested using Filebeat to read a file containing `{"source": {"ip": "10.13.14.15"}}`.

```auto
processors:
- decode_json_fields:
    fields: message
    target: ""
- add_fields:
    when.network.source.ip: '10.13.0.0/16'
    target: ''
    fields:
      source.geo.location:
        lat: 30.1
        lon: 70.33
      network.name: voice

```

You will get something like

```auto
{
    "@timestamp": "2020-05-07T13:52:05.799Z",
    "message": "{\"source\": {\"ip\": \"10.13.14.15\"}}",
    "network": {
      "name": "voice"
    },
    "source": {
      "geo": {
        "location": {
          "lat": 30.1,
          "lon": 70.33
        }
      },
      "ip": "10.13.14.15"
    }
  }

```

Another option might be to add `final_pipeline` to your index templates and force all incoming data through one ingest node pipeline that uses the [enrich processor](https://www.elastic.co/guide/en/elasticsearch/reference/master/geo-match-enrich-policy-type.html) to add this data. In theory you would create an index containing your network segments with geo data then enrich incoming events that match.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 2:12pm UTC](https://discuss.elastic.co/t/private-ip-geoip/225927/6 "2020-06-04T14:12:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
