| description | Look up Geo data from IP. |
|---|
{% hint style="info" %}
Supported event types: logs
{% endhint %}
The GeoIP2 filter lets you enrich the incoming data stream with location data from the GeoIP2 database.
The GeoLite2-City.mmdb database is available from MaxMind's official site.
This plugin supports the following configuration parameters:
| Key | Description |
|---|---|
database |
Path to the GeoIP2 database. |
lookup_key |
Field name to process. Multiple lookup_key entries are supported. |
record |
Defines the KEY LOOKUP_KEY VALUE triplet. |
The following configuration processes the incoming remote_addr and appends country information retrieved from the GeoLite2 database.
{% tabs %} {% tab title="fluent-bit.yaml" %}
pipeline:
inputs:
- name: dummy
dummy: {"remote_addr": "8.8.8.8"}
filters:
- name: geoip2
match: '*'
database: GeoLite2-City.mmdb
lookup_key: remote_addr
record:
- country remote_addr %{country.names.en}
- isocode remote_addr %{country.iso_code}
outputs:
- name: stdout
match: '*'{% endtab %} {% tab title="fluent-bit.conf" %}
[INPUT]
Name dummy
Dummy {"remote_addr": "8.8.8.8"}
[FILTER]
Name geoip2
Match *
Database GeoLite2-City.mmdb
Lookup_Key remote_addr
Record country remote_addr %{country.names.en}
Record isocode remote_addr %{country.iso_code}
[OUTPUT]
Name stdout
Match *
{% endtab %} {% endtabs %}
Each record parameter specifies the following triplet:
country: The field name to be added to records.remote_addr: The lookup key to process.%{country.names.en}: The GeoIP2 database query.
By running Fluent Bit with this configuration, you will see the following output:
{"remote_addr": "8.8.8.8", "country": "United States", "isocode": "US"}