# GeoIP Partially Functional

**URL:** <https://community.graylog.org/t/geoip-partially-functional/20171>\
**Category:** Graylog Central (peer support)\
**Created:** [June 12, 2021, 5:35pm UTC](https://community.graylog.org/t/geoip-partially-functional/20171 "2021-06-12T17:35:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hackdefendr](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/hackdefendr/32/3792_2.png) [@hackdefendr](https://community.graylog.org/u/hackdefendr)\
**Post date:** [June 12, 2021, 5:35pm UTC](https://community.graylog.org/t/geoip-partially-functional/20171/1 "2021-06-12T17:35:44Z")

</div>

Hi all,

I have a problem with the GeoIP pipeline configuration. Specifically the rule isn’t creating the custom fields I set for the Geo data. My log sources are two Nginx servers with custom JSON logging and fields. I used a content pack for this from the Marketplace, it was made for Graylog 3 and I am running Graylog 4.0.8 is the only real difference.

I have searched the google-sphere, which includes many many posts from this site, and I’m still not getting this to fully work. For GeoIP, I’m using the pipeline method, with all the pieces in place. Testing via the Lookup Tables test function I see results. The rule is correct as far as I can tell, here it is:

```auto
rule "remote_addr geoip lookup"
when
  has_field("remote_addr")
then
  let geo = lookup("geoip-lookup", to_string("remote_addr"));
  set_field("geo_location", geo["coordinates"]);
  set_field("geo_country_code", geo["country"].iso_code);
  set_field("geo_country_name", geo["country"].names.en);
  set_field("geo_city_name", geo["city"].names.en);
end

```

Yes, the field **remote\_addr** is correct. I have already extracted it properly into its own IP field. Based on several things I have read, as long as the field contains an IP address, then GeoIP will (should) work. Here is a screen grab showing the Lookup Table test. The IP was pulled from the logs:

 ![Screen Shot 2021-06-12 at 12.28.52 PM](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/4/4f9978b4dbdb5288376f7141e915837d4966c9c3.png)

Additionally, if I create a decorator from the Lookup Table in Configurations, the decoration field is created and populated when viewing a log’s details. The world map does not see this decoration field as usable.

I’m happy to share whatever is needed. I’m really hoping it is something simple.

Regards,  
Jeff

P.S. Is there a manual method for creating custom fields? Maybe if I force create the fields it will work?

J

---

<div class="post-metadata">

**Author:** ![hackdefendr](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/hackdefendr/32/3792_2.png) [@hackdefendr](https://community.graylog.org/u/hackdefendr)\
**Post date:** [June 12, 2021, 6:48pm UTC](https://community.graylog.org/t/geoip-partially-functional/20171/2 "2021-06-12T18:48:38Z")

</div>

Well if wonders never cease. Re-reading this article right here: [Geolocation via Pipelines in Graylog](https://blog.reconinfosec.com/geolocation-in-graylog/)

The answer to the problem and to finally solve this is… Order of Operation

Simply go to **SYSTEM → Configurations** and make sure the Pipeline processes _BEFORE_ the GeoIP Resolver. In fact, my GeoIP Resolver is last in the list.

Hope this stops the madness for someone 😉

Jeff

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 26, 2021, 6:49pm UTC](https://community.graylog.org/t/geoip-partially-functional/20171/3 "2021-06-26T18:49:12Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
