diff --git a/utils/logstash-kippo.conf b/utils/logstash-kippo.conf index b62629de..7b67adec 100644 --- a/utils/logstash-kippo.conf +++ b/utils/logstash-kippo.conf @@ -31,6 +31,12 @@ filter { add_field => [ "[geoip][coordinates]", "%{[geoip][longitude]}" ] add_field => [ "[geoip][coordinates]", "%{[geoip][latitude]}" ] } + + geoip { + source => "src_ip" + database => "/opt/logstash/vendor/geoip/GeoIPASNum.dat" + } + mutate { convert => [ "[geoip][coordinates]", "float" ] }