From c1808161e440eff3b1a334642c03d811d82b4817 Mon Sep 17 00:00:00 2001 From: t3chn0m4g3 Date: Wed, 7 Jun 2023 05:54:17 +0000 Subject: [PATCH] fixes #1346 --- docker/elk/logstash/dist/http_output.conf | 4 ++++ docker/elk/logstash/dist/logstash.conf | 4 ++++ 2 files changed, 8 insertions(+) diff --git a/docker/elk/logstash/dist/http_output.conf b/docker/elk/logstash/dist/http_output.conf index 4e103e1ae..70309fe2e 100644 --- a/docker/elk/logstash/dist/http_output.conf +++ b/docker/elk/logstash/dist/http_output.conf @@ -638,11 +638,13 @@ if "_jsonparsefailure" in [tags] { drop {} } geoip { cache_size => 10000 source => "src_ip" + default_database_type => "City" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-City.mmdb" } geoip { cache_size => 10000 source => "src_ip" + default_database_type => "ASN" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-ASN.mmdb" } translate { @@ -657,12 +659,14 @@ if "_jsonparsefailure" in [tags] { drop {} } cache_size => 10000 source => "t-pot_ip_ext" target => "geoip_ext" + default_database_type => "City" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-City.mmdb" } geoip { cache_size => 10000 source => "t-pot_ip_ext" target => "geoip_ext" + default_database_type => "ASN" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-ASN.mmdb" } } diff --git a/docker/elk/logstash/dist/logstash.conf b/docker/elk/logstash/dist/logstash.conf index 24d9af71a..1fda80a02 100644 --- a/docker/elk/logstash/dist/logstash.conf +++ b/docker/elk/logstash/dist/logstash.conf @@ -638,11 +638,13 @@ if "_jsonparsefailure" in [tags] { drop {} } geoip { cache_size => 10000 source => "src_ip" + default_database_type => "City" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-City.mmdb" } geoip { cache_size => 10000 source => "src_ip" + default_database_type => "ASN" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-ASN.mmdb" } translate { @@ -657,12 +659,14 @@ if "_jsonparsefailure" in [tags] { drop {} } cache_size => 10000 source => "t-pot_ip_ext" target => "geoip_ext" + default_database_type => "City" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-City.mmdb" } geoip { cache_size => 10000 source => "t-pot_ip_ext" target => "geoip_ext" + default_database_type => "ASN" # database => "/usr/share/logstash/vendor/bundle/jruby/2.6.0/gems/logstash-filter-geoip-7.2.12-java/vendor/GeoLite2-ASN.mmdb" } }