# Scripted fields to convert IP string to GeoIP?

**URL:** <https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243>\
**Category:** Kibana\
**Created:** [January 30, 2020, 4:40pm UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243 "2020-01-30T16:40:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul\_Kumar4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_kumar4/32/67369_2.png) [@Rahul\_Kumar4](https://discuss.elastic.co/u/Rahul_Kumar4)\
**Post date:** [January 30, 2020, 4:40pm UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243/1 "2020-01-30T16:40:38Z")

</div>

Is the possible to use Kibana Scripted fields (Using Painless) to convert an IP address field (that is currently indexed as a string) to a GeoJSON object (geoip datatype) field?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [January 30, 2020, 6:12pm UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243/2 "2020-01-30T18:12:03Z")

</div>

That is not possible. [Scripted fields](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) exist to compute results from field values. Scripted fields can not be used to look up additional values. In this instance, there is no way in painless to look up the geoip information for an IP address.

I would recommend using an ingest-pipeline to set up geoip, [https://www.elastic.co/guide/en/elasticsearch/reference/master/geoip-processor.html#using-ingest](https://www.elastic.co/guide/en/elasticsearch/reference/master/geoip-processor.html#using-ingest). Or using the [enrich processor](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/enrich-processor.html) to enrich documents in your index with geo-ip

---

<div class="post-metadata">

**Author:** ![Rahul\_Kumar4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_kumar4/32/67369_2.png) [@Rahul\_Kumar4](https://discuss.elastic.co/u/Rahul_Kumar4)\
**Post date:** [January 30, 2020, 6:46pm UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243/3 "2020-01-30T18:46:46Z")

</div>

Thank you.

---

<div class="post-metadata">

**Author:** ![Slavik\_Fursov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slavik_fursov/32/48975_2.png) [@Slavik\_Fursov](https://discuss.elastic.co/u/Slavik_Fursov)\
**Post date:** [January 30, 2020, 10:49pm UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243/4 "2020-01-30T22:49:51Z")

</div>

@Nathan_Reese  
Is this limitation by design?  
Why not enable scripts to run processors (such as geoip) the same way, as ingest pipeline can?

---

<div class="post-metadata">

**Author:** ![Rahul\_Kumar4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_kumar4/32/67369_2.png) [@Rahul\_Kumar4](https://discuss.elastic.co/u/Rahul_Kumar4)\
**Post date:** [January 30, 2020, 10:58pm UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243/5 "2020-01-30T22:58:25Z")

</div>

This would have been very useful in our use case where we simply have to convert an ip field from string to geo\_point. Reindexing supports using scripts but that too does not allow a geoip look up do, which makes the whole operation a little tedious. Curious to see what Nathan responds with.

If nothing works, we would have to rerun our existing indices through a logstash pipeline and index it back into ES.

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [January 31, 2020, 1:14am UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243/6 "2020-01-31T01:14:17Z")

</div>

Scripted fields run during query execution. The script is run for each document. Running something that has to perform a look up would be very resource intensive, greatly slow queries, and not scale. Its best to put all information into the document at ingest time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2020, 1:14am UTC](https://discuss.elastic.co/t/scripted-fields-to-convert-ip-string-to-geoip/217243/7 "2020-02-28T01:14:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
