GeoIP

Enrich events with GeoIP metadata

status: stable egress: stream state: stateless output: log

Configuration

Example configurations

{
  "transforms": {
    "my_transform_id": {
      "type": "geoip",
      "inputs": [
        "my-source-or-transform-id"
      ],
      "database": "/path/to/GeoLite2-City.mmdb",
      "source": "ip_address",
      "target": "geoip"
    }
  }
}
[transforms.my_transform_id]
type = "geoip"
inputs = [ "my-source-or-transform-id" ]
database = "/path/to/GeoLite2-City.mmdb"
source = "ip_address"
target = "geoip"
---
transforms:
  my_transform_id:
    type: geoip
    inputs:
      - my-source-or-transform-id
    database: /path/to/GeoLite2-City.mmdb
    source: ip_address
    target: geoip
{
  "transforms": {
    "my_transform_id": {
      "type": "geoip",
      "inputs": [
        "my-source-or-transform-id"
      ],
      "database": "/path/to/GeoLite2-City.mmdb",
      "source": "ip_address",
      "target": "geoip"
    }
  }
}
[transforms.my_transform_id]
type = "geoip"
inputs = [ "my-source-or-transform-id" ]
database = "/path/to/GeoLite2-City.mmdb"
source = "ip_address"
target = "geoip"
---
transforms:
  my_transform_id:
    type: geoip
    inputs:
      - my-source-or-transform-id
    database: /path/to/GeoLite2-City.mmdb
    source: ip_address
    target: geoip

database

required string
Path to the MaxMind GeoIP2 or GeoLite2 binary city database file (GeoLite2-City.mmdb). Other databases, such as the the country database, are not supported.

inputs

required [string]

A list of upstream source or transform IDs. Wildcards (*) are supported but must be the last character in the ID.

See configuration for more info.

Array string literal
Examples
[
  "my-source-or-transform-id",
  "prefix-*"
]

source

required string
The field name that contains the IP address. This field should contain a valid IPv4 or IPv6 address.

target

common optional string
The default field to insert the resulting GeoIP data into. See output for more info.
default: geoip

Output

Logs

Line

Geo-enriched log event
Fields
geoip required object
The root field containing all geolocation data as subfields. Depending on the database used, either the city or the ISP field is populated.

Telemetry

Metrics

link

events_in_total

counter
The number of events accepted by this component either from tagged origin like file and uri, or cumulatively from other origins.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.
container_name optional
The name of the container from which the event originates.
file optional
The file from which the event originates.
mode optional
The connection mode used by the component.
peer_addr optional
The IP from which the event originates.
peer_path optional
The pathname from which the event originates.
pod_name optional
The name of the pod from which the event originates.
uri optional
The sanitized URI from which the event originates.

events_out_total

counter
The total number of events emitted by this component.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.

processed_bytes_total

counter
The number of bytes processed by the component.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.
container_name optional
The name of the container from which the bytes originate.
file optional
The file from which the bytes originate.
mode optional
The connection mode used by the component.
peer_addr optional
The IP from which the bytes originate.
peer_path optional
The pathname from which the bytes originate.
pod_name optional
The name of the pod from which the bytes originate.
uri optional
The sanitized URI from which the bytes originate.

processed_events_total

counter
The total number of events processed by this component. This metric is deprecated in place of using events_in_total and events_out_total metrics.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.

processing_errors_total

counter
The total number of processing errors encountered by this component.
component_kind required
The Vector component kind.
component_name required
The Vector component name.
component_type required
The Vector component type.
error_type required
The type of the error

How it works

State

This component is stateless, meaning its behavior is consistent across each input.

Supported MaxMind databases

The geoip transform currently supports the following MaxMind databases:

  • GeoLite2-ASN.mmdb (free) — Determine the autonomous system number and organization associated with an IP address.
  • GeoLite2-City.mmdb (free) — Determine the country, subdivisions, city, and postal code associated with IPv4 and IPv6 addresses worldwide.
  • GeoIP2-City.mmdb (paid) — Determine the country, subdivisions, city, and postal code associated with IPv4 and IPv6 addresses worldwide.
  • GeoIP2-ISP.mmdb (paid) — Determine the Internet Service Provider (ISP), organization name, and autonomous system organization and number associated with an IP address.

The database files should be in the MaxMind DB file format.