# Using Filebeat with AWS ES with ingest-geoip disabled

**URL:** <https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 26, 2019, 4:04pm UTC](https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546 "2019-11-26T16:04:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chiemeleakoma](https://avatars.discourse-cdn.com/v4/letter/c/7ba0ec/32.png) [@chiemeleakoma](https://discuss.elastic.co/u/chiemeleakoma)\
**Post date:** [November 26, 2019, 4:04pm UTC](https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546/1 "2019-11-26T16:04:42Z")

</div>

I have setup filebeat with basic config as a proof of concept. After starting the service, i couldnt see any logs ingested by ES, but filebeat error log shows:

2019-11-26T15:56:28.174Z ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([http://xxx.eu-west-1.es.amazonaws.com:80](http://xxx.eu-west-1.es.amazonaws.com:80))): Connection marked as failed because the onConnect callback failed: Error loading pipeline for fileset iis/error: This module requires the following Elasticsearch plugins: ingest-geoip. You can install them by running the following commands on all the Elasticsearch nodes:  
sudo bin/elasticsearch-plugin install ingest-geoip.

From AWS ES specs, the ingest-geoip plugin is not supported. Is it possible to have filebeat running but with ingest-geoip disabled.

could be an optional feature, rather than a requirement.

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [November 26, 2019, 4:18pm UTC](https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546/2 "2019-11-26T16:18:04Z")

</div>

Thanks @chiemeleakoma! I saw you just commented on the github issue [https://github.com/elastic/beats/issues/10867](https://github.com/elastic/beats/issues/10867). We will triage it and prioritize it soon!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 27, 2019, 5:38am UTC](https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546/3 "2019-11-27T05:38:24Z")

</div>

Removing this plugin will mean that no location information will be derived from the IP information in the access logs, which is often very useful information. This will affect the usefulness of the dashboards as well. I would recommend using [Elastic's Elasticsearch service](https://www.elastic.co/cloud/) instead as it allows this plugin (and a lot of other features) and offers a free trial period.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 5:38am UTC](https://discuss.elastic.co/t/using-filebeat-with-aws-es-with-ingest-geoip-disabled/209546/4 "2019-12-25T05:38:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
