# Problems with geoip configuration

**URL:** <https://discuss.elastic.co/t/problems-with-geoip-configuration/28767>\
**Category:** Logstash\
**Created:** [September 7, 2015, 10:09am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767 "2015-09-07T10:09:26Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 7, 2015, 10:09am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/1 "2015-09-07T10:09:27Z")

</div>

Hi All

I've problems with mi geoip ip configuration, i've kibana 4.1.1 with logstash 1.5.3 and apache 2.4.

This is my personalized geoip file configuration on logstash, i called 12-geoip.conf :

filter {  
if [type] == "apache\_access" {  
grok {  
match =\> { "message" =\> "%{COMMONAPACHELOG}" }

}  
geoip {  
source =\> "clientip"  
target =\> "geoip.location"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip.location][coordinates]", "%{[geoip.location][longitude]}" ]  
add\_field =\> ["[geoip.location][coordinates]", "%{[geoip.location][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip.location][coordinates]", "float"]  
}  
}  
}

Mi apache configuration on other file  
filter {  
if [type] == "apache" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
add\_field =\> ["received\_from", "%{host}"]  
}  
}  
}

My problem is that Kibana don't appears the "geoip" field, but clientip, hostname, etc.... appears.

Part of my logstash-forwarder configuration

{  
"paths": [  
"/var/log/apache2/\*error.log",  
"/var/log/apache2/\*access-ssl.log"  
],  
"fields": { "type": "apache" }  
},  
{  
"paths": [  
"/var/log/apache2/\*access.log"  
],  
"fields": { "type": "apache\_access" }  
}  
]  
}

And my logstash-forwarder registered events:

2015/09/04 09:07:57.807119 Registrar: processing 5 events  
2015/09/04 09:08:45.244783 Registrar: processing 2 events  
2015/09/04 09:08:50.238178 Registrar: processing 2 events  
2015/09/04 09:09:02.744967 Registrar: processing 1 events

Thax so much.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 7, 2015, 10:15am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/2 "2015-09-07T10:15:10Z")

</div>

You shouldn't be using dots in your fieldnames like that, that will not be supported in ES 2.0.

What does the mapping for the field look like in ES?

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 7, 2015, 11:10am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/3 "2015-09-07T11:10:15Z")

</div>

Yes it's spanish.

I think that the problem resided in the filter configuration.

geoip {  
source =\> "clientip"  
target =\> "geoip.location"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip.location][coordinates]", "%{[geoip.location][longitude]}" ]  
add\_field =\> ["[geoip.location][coordinates]", "%{[geoip.location][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip.location][coordinates]", "float"]  
}

I don't see the field on kibana server, but for example the clientip appears

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 7, 2015, 11:16am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/4 "2015-09-07T11:16:31Z")

</div>

You need to get the mapping for the index and then look at the field.

`curl -XGET localhost:9200/indexname/_mapping`

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 7, 2015, 1:20pm UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/5 "2015-09-07T13:20:39Z")

</div>

The field is geoip, my index name called logstash-\*

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 7, 2015, 9:25pm UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/6 "2015-09-07T21:25:52Z")

</div>

Ok, so did you check the mapping for that field?

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 8, 2015, 7:19am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/7 "2015-09-08T07:19:53Z")

</div>

I don't understand, should be work with this configuration

filter {  
if [type] == "apache\_access" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}

I saw on kibana the client ip, my field for geoip is "geoip" i don't know that wrong.

"apache\_access" \_type works correctly, i saw that on kibana, was configurated on logstash-forwarder.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 8, 2015, 8:06am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/8 "2015-09-08T08:06:08Z")

</div>

In Elasticsearch you map a field, this is where you tell it that any data in your geoip field is actually a geoip type, which is how KB then knows how to use that to put it on the map.

You need to check that field to make sure it is mapped correctly. `curl host:9200/INDEXNAME/_mapping` should show you.

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 8, 2015, 8:44am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/9 "2015-09-08T08:44:31Z")

</div>

Warkolm so many thanks for your help 😬

I executed the curl host:9200/INDEXNAME/\_mapping with my index, and filtered the command output i saw the geoip field, but is so curious i don't see the ip, clientip or ip address field.

"geoip":{"dynamic":"true","properties":{"location":{"type":"geo\_point"}}}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 8, 2015, 8:47am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/10 "2015-09-08T08:47:56Z")

</div>

> [@dfaropennetwork](#):
>
> geoip.location

Originally you mentioned you were using the above field, is it that or is it `geoip`?

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 8, 2015, 8:51am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/11 "2015-09-08T08:51:23Z")

</div>

On kibana interface appears with the name "geoip.location" but with the analyced column set to false.

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 14, 2015, 11:04am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/12 "2015-09-14T11:04:37Z")

</div>

At the moment i see the "geoip" field in my "index" but i don't see that on kibana.

filter {  
if [type] == "apache\_access" {  
grok {  
pattern =\> "%{COMBINEDAPACHELOG}"  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}  
}  
}

curl -XGET 10.29.0.71:9200/logstash-\*/\_mapping

"geoip":{"dynamic":"true","properties":{"location":{"type":"geo\_point"}}},

Some idea?

Thx

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 14, 2015, 11:21am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/13 "2015-09-14T11:21:27Z")

</div>

Sorry i don't saw the specific index for my apache\_access, but it's the good one

{  
"apache\_access-logstash-2015.09.08" : {  
"mappings" : {  
"apache\_access" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"@version" : {  
"type" : "string"  
},  
"agent" : {  
"type" : "string"  
},  
"auth" : {  
"type" : "string"  
},  
"bytes" : {  
"type" : "string"  
},  
"clientip" : {  
"type" : "string"  
},  
"file" : {  
"type" : "string"  
},  
"host" : {  
"type" : "string"  
},  
"httpversion" : {  
"type" : "string"  
},  
"ident" : {  
"type" : "string"  
},  
"message" : {  
"type" : "string"  
},  
"offset" : {  
"type" : "string"  
},  
"referrer" : {  
"type" : "string"  
},  
"request" : {  
"type" : "string"  
},  
"response" : {  
"type" : "string"  
},  
"timestamp" : {  
"type" : "string"  
},  
"type" : {  
"type" : "string"  
},  
"verb" : {  
"type" : "string"  
}  
}  
}  
}  
}  
}

And i don't see the geoip or geo\_point field, some idea?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 14, 2015, 8:54pm UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/14 "2015-09-14T20:54:11Z")

</div>

If that above mapping is the index you are trying to use geo mapping on, it has no geo field.  
You'd need to check your Logstash config.

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 15, 2015, 8:24am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/15 "2015-09-15T08:24:53Z")

</div>

I don't know where i should set geo mapping turn on, i checked my logstash configuration but i don't see anything row 😔, maybe my index configuration is wrong.

When logstash catch my apache access log and parse the log should convert the "clientip" on geoip location

COMMONAPACHELOG %{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-)

{"type":"string","index":"not\_analyzed","ignore\_above":256}}},"geoip":{"dynamic":"true","properties":{"location":{"type":"geo\_point"}}},"host":{"type":"string","norms":

I don't know because clinetip and geoip index mappings appears disable:

"clientip" : {  
"type" : "string",  
"norms" : {  
"enabled" : false  
},  
"geoip" : {  
"dynamic" : "true",  
"properties" : {  
"location" : {  
"type" : "geo\_point"  
}  
}

Can i create my own index? always appears with the syntax "logstash-date"

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 15, 2015, 8:31am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/16 "2015-09-15T08:31:05Z")

</div>

On kibana geoip.location appear configured as indexed but not analyced.

FInally i configured my own index.

output {  
elasticsearch { host =\> "marioneto01"  
cluster =\> "oknels"  
action =\> "index"  
index =\> "oknindex-%{+dd.MM.YYYY}"}  
stdout { codec =\> rubydebug }  
}

The mappings are:

{  
"oknindex-15.09.2015" : {  
"mappings" : {  
"apache\_access" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"@version" : {  
"type" : "string"  
},  
"agent" : {  
"type" : "string"  
},  
"auth" : {  
"type" : "string"  
},  
"bytes" : {  
"type" : "string"  
},  
"clientip" : {  
"type" : "string"  
},  
"file" : {  
"type" : "string"  
},  
"host" : {  
"type" : "string"  
},  
"httpversion" : {  
"type" : "string"  
},  
"ident" : {  
"type" : "string"  
},  
"message" : {  
"type" : "string"  
},  
"offset" : {  
"type" : "string"  
},  
"referrer" : {  
"type" : "string"  
},  
"request" : {  
"type" : "string"  
},  
"response" : {  
"type" : "string"  
},  
"timestamp" : {  
"type" : "string"  
},  
"type" : {  
"type" : "string"  
},  
"verb" : {  
"type" : "string"  
}  
}  
},  
"syslog" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"@version" : {  
"type" : "string"  
},  
"file" : {  
"type" : "string"  
},  
"host" : {  
"type" : "string"  
},  
"message" : {  
"type" : "string"  
},  
"offset" : {  
"type" : "string"  
},  
"received\_at" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"received\_from" : {  
"type" : "string"  
},  
"syslog\_facility" : {  
"type" : "string"  
},  
"syslog\_facility\_code" : {  
"type" : "long"  
},  
"syslog\_hostname" : {  
"type" : "string"  
},  
"syslog\_message" : {  
"type" : "string"  
},  
"syslog\_pid" : {  
"type" : "string"  
},  
"syslog\_program" : {  
"type" : "string"  
},  
"syslog\_severity" : {  
"type" : "string"  
},  
"syslog\_severity\_code" : {  
"type" : "long"  
},  
"syslog\_timestamp" : {  
"type" : "string"  
},  
"type" : {  
"type" : "string"  
}  
}  
}  
}  
}  
}

My apache and my apache\_access on logstash is configured on diferents files:

filter {  
if [type] == "apache\_error" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
add\_field =\> ["received\_from", "%{host}"]  
}  
}  
}

filter {  
if [type] == "apache\_access" {  
grok {  
match =\> {"message" =\> "%{COMBINEDAPACHELOG}" }  
}  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}  
}

The geoip location on kibana don't appear

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 15, 2015, 9:15am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/17 "2015-09-15T09:15:42Z")

</div>

What does the output look like, the json before it's pushed into ES?  
Use stdout with rubydebug to check.

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 15, 2015, 9:30am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/18 "2015-09-15T09:30:15Z")

</div>

> [@warkolm](#):
>
> What does the output look like, the json before it's pushed into ES?Use stdout with rubydebug to check.

I had debug output configured:

'[DEPRECATED] use `require 'concurrent'` instead of `require 'concurrent_ruby'`  
[2015-09-15 11:25:57.851] WARN -- Concurrent: [DEPRECATED] Java 7 is deprecated, please use Java 8.  
Java 7 support is only best effort, it may not work. It will be removed in next release (1.0).  
[2015-09-15 11:25:58.577] WARN -- Concurrent::Condition: [DEPRECATED] Will be replaced with Synchronization::Object in v1.0.  
called on: /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-lumberjack-1.0.2/lib/logstash/sized\_queue\_timeout.rb:15:in `initialize' [2015-09-15 11:25:58.579] WARN -- Concurrent::Condition: [DEPRECATED] Will be replaced with Synchronization::Object in v1.0. called on: /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-lumberjack-1.0.2/lib/logstash/sized_queue_timeout.rb:16:in `initialize'  
sep 15, 2015 11:26:00 AM org.elasticsearch.node.internal.InternalNode   
INFORMACIÓN: [logstash-marioneto01-6297-11634] version[1.7.0], pid[6297], build[929b973/2015-07-16T14:31:07Z]  
sep 15, 2015 11:26:00 AM org.elasticsearch.node.internal.InternalNode   
INFORMACIÓN: [logstash-marioneto01-6297-11634] initializing ...  
sep 15, 2015 11:26:01 AM org.elasticsearch.plugins.PluginsService   
INFORMACIÓN: [logstash-marioneto01-6297-11634] loaded , sites   
sep 15, 2015 11:26:02 AM org.elasticsearch.bootstrap.Natives   
ADVERTENCIA: JNA not found. native methods will be disabled.  
sep 15, 2015 11:26:03 AM org.elasticsearch.node.internal.InternalNode   
INFORMACIÓN: [logstash-marioneto01-6297-11634] initialized  
sep 15, 2015 11:26:03 AM org.elasticsearch.node.internal.InternalNode start  
INFORMACIÓN: [logstash-marioneto01-6297-11634] starting ...  
sep 15, 2015 11:26:03 AM org.elasticsearch.transport.TransportService doStart  
INFORMACIÓN: [logstash-marioneto01-6297-11634] bound\_address {inet[/0:0:0:0:0:0:0:0:9301]}, publish\_address {inet[/10.29.0.71:9301]}  
sep 15, 2015 11:26:03 AM org.elasticsearch.discovery.DiscoveryService doStart  
INFORMACIÓN: [logstash-marioneto01-6297-11634] oknels/8JA1K1caSjW5LdCSXShU9A  
sep 15, 2015 11:26:06 AM org.elasticsearch.cluster.service.InternalClusterService$UpdateTask run  
INFORMACIÓN: [logstash-marioneto01-6297-11634] detected\_master [Gregory Gideon][HWQyrgxoTQieSesu9NPClw][marioneto01][inet[/10.29.0.71:9300]], added {[Gregory Gideon][HWQyrgxoTQieSesu9NPClw][marioneto01][inet[/10.29.0.71:9300]],}, reason: zen-disco-receive(from master [[Gregory Gideon][HWQyrgxoTQieSesu9NPClw][marioneto01][inet[/10.29.0.71:9300]]])  
sep 15, 2015 11:26:06 AM org.elasticsearch.node.internal.InternalNode start  
INFORMACIÓN: [logstash-marioneto01-6297-11634] started

At the moment i configured my own index:

output {  
elasticsearch {  
host =\> "marioneto01"  
cluster =\> "oknels"  
action =\> "index"  
index =\> "oknindex-%{+dd.MM.YYYY}"  
template =\> "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-1.0.5-java/lib/logstash/outputs/elasticsearch/elasticsearch-oknindex-template.json"  
template\_name =\> "oknindex" }  
stdout { codec =\> rubydebug }  
}

I created a template:

{  
"template" : "oknindex",  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : true, "omit\_norms" : true},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true  
}  
}  
}, {  
"string\_fields" : {  
"match" : "\*",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true,  
"fields" : {  
"raw" : {"type": "string", "index" : "not\_analyzed", "ignore\_above" : 256}  
}  
}  
}  
} ],  
"properties" : {  
"@version": { "type": "string", "index": "not\_analyzed" },  
"geoip" : {  
"type" : "object",  
"dynamic": true,  
"properties" : {  
"location" : { "type" : "geoip" }  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 15, 2015, 9:30am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/19 "2015-09-15T09:30:28Z")

</div>

But now the field are empthy

curl '10.29.0.71:9200/okn\*/\_mapping/?pretty'  
{  
"oknindex-15.09.2015" : {  
"mappings" : {  
"apache\_access" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"@version" : {  
"type" : "string"  
},  
"agent" : {  
"type" : "string"  
},  
"auth" : {  
"type" : "string"  
},  
"bytes" : {  
"type" : "string"  
},  
"clientip" : {  
"type" : "string"  
},  
"file" : {  
"type" : "string"  
},  
"host" : {  
"type" : "string"  
},  
"httpversion" : {  
"type" : "string"  
},  
"ident" : {  
"type" : "string"  
},  
"message" : {  
"type" : "string"  
},  
"offset" : {  
"type" : "string"  
},  
"referrer" : {  
"type" : "string"  
},  
"request" : {  
"type" : "string"  
},  
"response" : {  
"type" : "string"  
},  
"timestamp" : {  
"type" : "string"  
},  
"type" : {  
"type" : "string"  
},  
"verb" : {  
"type" : "string"  
}  
}  
},  
"syslog" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"@version" : {  
"type" : "string"  
},  
"file" : {  
"type" : "string"  
},  
"host" : {  
"type" : "string"  
},  
"message" : {  
"type" : "string"  
},  
"offset" : {  
"type" : "string"  
},  
"received\_at" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"received\_from" : {  
"type" : "string"  
},  
"syslog\_facility" : {  
"type" : "string"  
},  
"syslog\_facility\_code" : {  
"type" : "long"  
},  
"syslog\_hostname" : {  
"type" : "string"  
},  
"syslog\_message" : {  
"type" : "string"  
},  
"syslog\_pid" : {  
"type" : "string"  
},  
"syslog\_program" : {  
"type" : "string"  
},  
"syslog\_severity" : {  
"type" : "string"  
},  
"syslog\_severity\_code" : {  
"type" : "long"  
},  
"syslog\_timestamp" : {  
"type" : "string"  
},  
"type" : {  
"type" : "string"  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [September 15, 2015, 9:32am UTC](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767/20 "2015-09-15T09:32:33Z")

</div>

But on my kibana i saw the fields complement with the correct information excepting geoip

[Next page](https://discuss.elastic.co/t/problems-with-geoip-configuration/28767.md?page=2)
