# System.auth.ssh.geoip.country\_iso\_code Field not Available in auth log

**URL:** <https://discuss.elastic.co/t/system-auth-ssh-geoip-country-iso-code-field-not-available-in-auth-log/151418>\
**Category:** Logstash\
**Created:** [October 8, 2018, 9:30am UTC](https://discuss.elastic.co/t/system-auth-ssh-geoip-country-iso-code-field-not-available-in-auth-log/151418 "2018-10-08T09:30:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 8, 2018, 9:30am UTC](https://discuss.elastic.co/t/system-auth-ssh-geoip-country-iso-code-field-not-available-in-auth-log/151418/1 "2018-10-08T09:30:00Z")

</div>

Hello Team,

I am using Filebeat to send the system log on kibana dashboard. Logs are reporting on kibana dashbord properly. But i am not getting the field **system.auth.ssh.geoip.country\_iso\_code** on kibana. So its not showing on SSH dashboard.

Please refer the below screenshot:

 ![Selection_046](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e31460be7b0c94bef85ef1009f60111d75c885af.png)

But we want this filed so we can easily recognize from where somebody access or tried SSH our server.

Below is my grok pattern for auth log:

```auto
grok {
match => { "message" => ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} %{DATA:[system][auth][ssh][method]} for (invalid user )?%{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]} port %{NUMBER:[system][auth][ssh][port]} ssh2(: %{GREEDYDATA:[system][auth][ssh][signature]})?", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} user %{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: Did not receive identification string from %{IPORHOST:[system][auth][ssh][dropped_ip]}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:\[%{POSINT:[system][auth][pid]}\])?: \s*%{DATA:[system][auth][user]} :( %{DATA:[system][auth][sudo][error]} ;)? TTY=%{DATA:[system][auth][sudo][tty]} ; PWD=%{DATA:[system][auth][sudo][pwd]} ; USER=%{DATA:[system][auth][sudo][user]} ; COMMAND=%{GREEDYDATA:[system][auth][sudo][command]}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:\[%{POSINT:[system][auth][pid]}\])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:\[%{POSINT:[system][auth][pid]}\])?: new user: name=%{DATA:[system][auth][user][add][name]}, UID=%{NUMBER:[system][auth][user][add][uid]}, GID=%{NUMBER:[system][auth][user][add][gid]}, home=%{DATA:[system][auth][user][add][home]}, shell=%{DATA:[system][auth][user][add][shell]}$", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:\[%{POSINT:[system][auth][pid]}\])?: %{GREEDYMULTILINE:[system][auth][message]}"] }

```

I have tried to make changes in Visualize also for SSH Login Attempts dashboard but no success.  
Can you please let me know what i need to add in my Grok pattern to get this filed?

Thanks.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 9, 2018, 3:27am UTC](https://discuss.elastic.co/t/system-auth-ssh-geoip-country-iso-code-field-not-available-in-auth-log/151418/2 "2018-10-09T03:27:08Z")

</div>

Hello Team,  
Can you please help me on above issue?

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 3:27am UTC](https://discuss.elastic.co/t/system-auth-ssh-geoip-country-iso-code-field-not-available-in-auth-log/151418/3 "2018-11-06T03:27:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
