# Translate private ip to geo location using external dictionary

**URL:** <https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710>\
**Category:** Logstash\
**Created:** [May 1, 2020, 12:12pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710 "2020-05-01T12:12:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 1, 2020, 12:12pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710/1 "2020-05-01T12:12:05Z")

</div>

Hi all,

I'm trying to follow example in this link [https://discuss.elastic.co/t/private-ip-geoip-from-dictionary/156763](https://discuss.elastic.co/t/private-ip-geoip-from-dictionary/156763), however I can't seem to make it work. Basically I want to translate private ip address using external dictionary path.

Here's my translate filter config :

```auto
 translate {
      exact => true
      regex => true 
      field => "[source][ip]"
      destination => "[source][geo]"
      dictionary_path => "./geo.yml"
    }

```

And here's the dictionary file :

```auto
`'10.5.181.74': '{"geoip":{"timezone":"Asia/Jakarta","continent_code":"NA","country_name":"Indonesia","region_code":"JK","country_code2":"ID","country_code3":"ID","region_name":"Jakarta","city_name":"Jakarta","latitude":-6.196459,"longitude":106.822451,"location":{"lat":-6.196459,"lon":106.822451}}}'`

```

I'm expecting the geo to be mapped to source.geo field, but it didn't. this is the output.

```auto
    "source" => {
            "geo" => "{\"geoip\":{\"timezone\":\"Asia/Jakarta\",\"continent_code\":\"NA\",\"country_name\":\"Indonesia\",\"region_code\":\"JK\",\"country_code2\":\"ID\",\"country_code3\":\"ID\",\"region_name\":\"Jakarta\",\"city_name\":\"Jakarta\",\"latitude\":-6.196459,\"longitude\":106.822451,\"location\":{\"lat\":-6.196459,\"lon\":106.822451}}}",
             "ip" => "10.5.181.74"
        },

```

any pointers?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 1, 2020, 1:07pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710/2 "2020-05-01T13:07:43Z")

</div>

That looks like it worked perfectly. What is the problem?

---

<div class="post-metadata">

**Author:** ![ppafford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppafford/32/36533_2.png) [@ppafford](https://discuss.elastic.co/u/ppafford)\
**Post date:** [May 2, 2020, 5:46pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710/3 "2020-05-02T17:46:43Z")

</div>

I think it's your translate, it looks to be doing what you coded but I think you're wanting this to be a geoip location. se the translation Im doing here, I think this will put you on the right path [Private ip geoip from dictionary](https://discuss.elastic.co/t/private-ip-geoip-from-dictionary/156763/7)

```
destination => "geo_point"
```

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 2, 2020, 9:23pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710/4 "2020-05-02T21:23:16Z")

</div>

the translation worked, but it stored the geo coordinates as string rather than a geo location

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 2, 2020, 9:26pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710/5 "2020-05-02T21:26:40Z")

</div>

nope, still didn't solve it. trying your suggestion creates a new field called "geo\_point" with the value of coordinates as a string :

```auto
if "src_internal_ip" in [tags] {
    translate {
      exact => true
      regex => true 
      field => "[source][ip]"
      destination => "geo_point"
      dictionary_path => "./geo.yml"
    }
  }

```

output :

```auto
"geo_point" => "{\"geoip\":{\"timezone\":\"Asia/Jakarta\",\"continent_code\":\"NA\",\"country_name\":\"Indonesia\",\"region_code\":\"JK\",\"country_code2\":\"ID\",\"country_code3\":\"ID\",\"region_name\":\"Jakarta\",\"city_name\":\"Jakarta\",\"latitude\":-6.196459,\"longitude\":106.822451,\"location\":{\"lat\":-6.196459,\"lon\":106.822451}}}",
       "fw_rule_id" => "0",

```

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 2, 2020, 10:20pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710/6 "2020-05-02T22:20:54Z")

</div>

my mistake, i need to parse the resulting json using json filter. missed this part from the original post. here's working config :

```auto
if "src_internal_ip" in [tags] {
    translate {
      exact => true
      regex => true 
      override => true
      refresh_behaviour => "replace"
      field => "[source][ip]"
      destination => "geo_point"
      dictionary_path => "./geo.yml"
    }

    json {
      source => "geo_point"
      target => "[source][geo]"
    }
  }

```

output:

```auto
"source" => {
         "ip" => "10.5.181.74",
        "geo" => {
            "geoip" => {
                     "city_name" => "Jakarta",
                   "region_code" => "JK",
                     "longitude" => 106.822451,
                      "location" => {
                    "lat" => -6.196459,
                    "lon" => 106.822451
                },
                  "country_name" => "Indonesia",
                 "country_code3" => "ID",
                      "latitude" => -6.196459,
                   "region_name" => "Jakarta",
                 "country_code2" => "ID",
                      "timezone" => "Asia/Jakarta",
                "continent_code" => "NA"
            }
        }

```

thanks @ppafford for the post

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2020, 10:20pm UTC](https://discuss.elastic.co/t/translate-private-ip-to-geo-location-using-external-dictionary/230710/7 "2020-05-30T22:20:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
