Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GeoIP informations mapped for wrong IP #183

Open
Enrico204 opened this issue May 12, 2019 · 4 comments · May be fixed by #184
Open

GeoIP informations mapped for wrong IP #183

Enrico204 opened this issue May 12, 2019 · 4 comments · May be fixed by #184

Comments

@Enrico204
Copy link

The GeoIP information are extracted from the destination IP only (I think that this is caused by the logstash configuration, which logs the geoip result with the same key for source and destination IPs). In my opinion, these informations should be divided in geoip_src and geoip_dest.

My setup is SELKS with a secondary NIC for passive interception (the NIC is linked to a SPAN/mirror port in the switch)

@pevma
Copy link
Member

pevma commented May 13, 2019

This is the part of the logstash config that you refer to right - https://github.com/StamusNetworks/SELKS/blob/master/staging/etc/logstash/conf.d/logstash.conf#L50 ?

@Enrico204
Copy link
Author

Yes - sorry, I'm not a logstash expert, but AFAIK lines 59-67 will override 50-58. I made a test renaming field at 62 (and re-creating the index in Kibana) and it seems to work properly, but I think that it should be the default :-)

@pevma
Copy link
Member

pevma commented May 13, 2019

aha ok. Could you please do a pull request towards the git master for review?

@Enrico204
Copy link
Author

I will ASAP :-)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants