Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GeoLitePrivate2-City.mmdb doesn't exist #366

Closed
anubisg1 opened this issue Oct 30, 2022 · 3 comments
Closed

GeoLitePrivate2-City.mmdb doesn't exist #366

anubisg1 opened this issue Oct 30, 2022 · 3 comments
Labels
documentation Improvements or additions to documentation question Further information is requested

Comments

@anubisg1
Copy link
Contributor

to use the geoip enrichment, you need to files, specifically

          database => "/mnt/s3fs_geoip/GeoLite2-City.mmdb"
          database => "/mnt/s3fs_geoip/GeoLitePrivate2-City.mmdb"

unfortunately seems like GeoLitePrivate2-City.mmdb doesn't exist anywhere in the internet and maxmind only provides

  • GeoLite2-ASN.mmdb
  • GeoLite2-City.mmdb
  • GeoLite2-Country.mmdb

i'd expect that either more information on where to find GeoLitePrivate2-City.mmdb is added to the documentation or the enrichment pipeline is updated to function without that file

@brian-grabau
Copy link
Contributor

Correct you have to subscribe and get your own copy, I cannot redistribute
https://www.elastic.co/guide/en/logstash/current/plugins-filters-geoip.html

@anubisg1
Copy link
Contributor Author

anubisg1 commented Nov 2, 2022

Hi,

maybe i wasn't clear.. when you subscribe and download the geoip databases, you can download only

  • GeoLite2-ASN.mmdb
  • GeoLite2-City.mmdb
  • GeoLite2-Country.mmdb

the DB that the enrichment pipeline requires, specifically GeoLitePrivate2-City.mmdb is not provided by maxmind.

@KrishnanandSingh
Copy link
Member

Yeah the files aren't present in the repo. It is also mentioned here that you need to add them yourself https://github.com/Cargill/OpenSIEM-Logstash-Parsing/tree/1.0/build_scripts#getting-started

The private geoip file is what we created for us with the internal network information we have to be used inside Cargill. Distributing that would be sensitive to Cargill and useless for others. You can use the maxmind writer to create a private geoip file yourself.

@KrishnanandSingh KrishnanandSingh added documentation Improvements or additions to documentation question Further information is requested labels Dec 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation question Further information is requested
Projects
None yet
Development

No branches or pull requests

3 participants