Skip to content

Feature: GeoIP pipeline — short country labels + composite geo_hit for Top-N tables #308

Description

@SemoTech

Context

SemoTech — self-hosted LogTide v1.3.2, Caddy WAN Geography dashboard (Vector → LogTide, GeoIP pipeline on client_ip).

We use Top-N table panels with dimension: metadata and a flat key for ranked locations + hit counts (#299). v1.3.2 time-range picker (#305) works well. Thank you for shipping both.

Today we work around two display gaps with a bind-mounted patch to log-pipeline/steps/geoip.js on backend + worker. We would rather drop the patch and use native behavior.

Problem 1 — geo_place includes coordinates in the human label

The GeoIP step writes geo_place as:

41.90,12.50|Rome, Italy

That format is correct for geo_map points mode (single group-by key). For Top-N tables, operators want the label without lat/lon:

Rome, Italy (or Rome, USA)

We currently derive geo_label in our patch by stripping the coordinate prefix.

Problem 2 — Top-N needs location and connection target in one dimension

Top-N panels accept a single metadata key. We want rows like:

New York, USA → host.domain.com - agent

not the full URL (https://host.domain.com/agents/…), which explodes cardinality on agent heartbeats.

Our patch adds geo_hit built from:

  • short place label (City, USA)
  • simplified target from existing ingest metadata (http_host, http_uri, hit_class, http_meaning), e.g. host.domain.com - agent | portal | blocked | website

Proposal

Extend the geoip pipeline step (or a small optional follow-on step) to emit:

Key Example Used by
geo_place 40.72,-74.00|New York, United States geo_map (unchanged)
geo_label New York, USA top_n_table, log_table
geo_hit New York, USA → host.domain.com - agent top_n_table (optional; only when http_host present)

Country shortening: optional locale/short-name map (United States → USA, United Kingdom → UK) — config flag on the geoip step, default off for backward compatibility.

Connection target: derive a low-cardinality role from request metadata already on the log (host + path class), not full URI. Suggested roles: agent, portal, website, blocked, site (fallback). Could be a simple rules table in step config or sensible defaults.

Why not multiple Top-N columns?

LogTide Top-N is one dimension today; composite string keeps one panel and matches Graylog-style “location + what they hit” summaries.

Our workaround today (for context only — not asking LogTide to support bind mounts)

volumes:
  - /opt/LogTide/geolite2:/app/packages/backend/data/geolite2
  - /opt/LogTide/patches/geoip.js:/app/packages/backend/dist/modules/log-pipeline/steps/geoip.js:ro

Patch must be re-verified on every image upgrade. Native keys would remove this ops burden.

Acceptance ideas

  • geo_label emitted by geoip step (coords stripped; optional short country names)
  • Optional geo_hit when http_host (and optionally path) exists in metadata at pipeline time
  • Documented in pipeline UI + Top-N metadata field picker examples
  • No breaking change to existing geo_place / geo_map behavior

Happy to test on our WAN dashboard from a dev build or next release.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions