# Unable to source and feed in the correct information in src country

**URL:** <https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019>\
**Category:** SIEM\
**Created:** [July 30, 2024, 4:53am UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019 "2024-07-30T04:53:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![SandeshS](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@SandeshS](https://discuss.elastic.co/u/SandeshS)\
**Post date:** [July 30, 2024, 4:53am UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019/1 "2024-07-30T04:53:59Z")

</div>

Hi all,

How do I get correct country source in all my fortigate logs? Currently all my logins are showing from a random country for VPN.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 30, 2024, 7:23am UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019/2 "2024-07-30T07:23:43Z")

</div>

From #Elasticsearch to #SIEM

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 30, 2024, 7:23am UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019/3 "2024-07-30T07:23:43Z")

</div>

Removed #elastic-stack-monitoring, #elastic-stack-security

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 30, 2024, 7:24am UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019/4 "2024-07-30T07:24:09Z")

</div>

I've moved this to the `SIEM` forum

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [August 2, 2024, 5:06pm UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019/5 "2024-08-02T17:06:42Z")

</div>

Hi @SandeshS

Did you read [GeoIP processor | Elasticsearch Guide [8.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.14/geoip-processor.html)

I'm not using Fortigate but it works for other firewalls like panw. It should work for you when:

- `ingest.geoip.downloader.eager.download` is set to true
- your fortigate pipeline uses a `geoip` processor

Check your elasticsearch logs if it doesn't work (and your firewall logs, maybe you are blocking [https://geoip.elastic.co/v1/database](https://geoip.elastic.co/v1/database?elastic_geoip_service_tos=agree) )

Willem

---

<div class="post-metadata">

**Author:** ![SandeshS](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@SandeshS](https://discuss.elastic.co/u/SandeshS)\
**Post date:** [August 4, 2024, 11:05pm UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019/6 "2024-08-04T23:05:37Z")

</div>

Hi @willemdh, thank you for the suggestion. But as I'm totally unaware, can you help me tell where I can make this change?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2024, 11:05pm UTC](https://discuss.elastic.co/t/unable-to-source-and-feed-in-the-correct-information-in-src-country/364019/7 "2024-09-01T23:05:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
