Closed panks21 closed 1 year ago
You would need to amend the docker-compose.yml file (after line 231). Adding the location of the maxmind databases. Then you’d need to amend the 30-geoip.pfelk file, pointing to the alternate location (eg maxmind database files).
looks like this..
logstash: depends_on:
@charlesw23
The following ought to work given that GeoIP is installed at /usr/share/GeoIP
but I believe the default location is /var/lib/GeoIP/
In addition to the amendment within the .yml you'll need to uncommit the #MRM#
from the 30-geoip.pfelk file.
volumes:
- ./certs:/certs:z
- ./etc/logstash/config/:/usr/share/logstash/config:ro
- ./etc/pfelk/conf.d/:/etc/pfelk/conf.d:ro
- ./etc/pfelk/patterns/:/etc/pfelk/patterns:ro
- ./etc/pfelk/databases/:/etc/pfelk/databases:ro
- /usr/share/GeoIP/:/var/lib/GeoIP:ro
ports:
Not an issue but a question. Where do we setup the maxmind geoip in the docker-compose file??