Context
SemoTech — self-hosted LogTide v1.3.2, Caddy WAN Geography dashboard (Vector → LogTide, GeoIP pipeline on client_ip).
We use Top-N table panels with dimension: metadata and a flat key for ranked locations + hit counts (#299). v1.3.2 time-range picker (#305) works well. Thank you for shipping both.
Today we work around two display gaps with a bind-mounted patch to log-pipeline/steps/geoip.js on backend + worker. We would rather drop the patch and use native behavior.
Problem 1 — geo_place includes coordinates in the human label
The GeoIP step writes geo_place as:
41.90,12.50|Rome, Italy
That format is correct for geo_map points mode (single group-by key). For Top-N tables, operators want the label without lat/lon:
Rome, Italy (or Rome, USA)
We currently derive geo_label in our patch by stripping the coordinate prefix.
Problem 2 — Top-N needs location and connection target in one dimension
Top-N panels accept a single metadata key. We want rows like:
New York, USA → host.domain.com - agent
not the full URL (https://host.domain.com/agents/…), which explodes cardinality on agent heartbeats.
Our patch adds geo_hit built from:
- short place label (
City, USA)
- simplified target from existing ingest metadata (
http_host, http_uri, hit_class, http_meaning), e.g. host.domain.com - agent | portal | blocked | website
Proposal
Extend the geoip pipeline step (or a small optional follow-on step) to emit:
| Key |
Example |
Used by |
geo_place |
40.72,-74.00|New York, United States |
geo_map (unchanged) |
geo_label |
New York, USA |
top_n_table, log_table |
geo_hit |
New York, USA → host.domain.com - agent |
top_n_table (optional; only when http_host present) |
Country shortening: optional locale/short-name map (United States → USA, United Kingdom → UK) — config flag on the geoip step, default off for backward compatibility.
Connection target: derive a low-cardinality role from request metadata already on the log (host + path class), not full URI. Suggested roles: agent, portal, website, blocked, site (fallback). Could be a simple rules table in step config or sensible defaults.
Why not multiple Top-N columns?
LogTide Top-N is one dimension today; composite string keeps one panel and matches Graylog-style “location + what they hit” summaries.
Our workaround today (for context only — not asking LogTide to support bind mounts)
volumes:
- /opt/LogTide/geolite2:/app/packages/backend/data/geolite2
- /opt/LogTide/patches/geoip.js:/app/packages/backend/dist/modules/log-pipeline/steps/geoip.js:ro
Patch must be re-verified on every image upgrade. Native keys would remove this ops burden.
Acceptance ideas
Happy to test on our WAN dashboard from a dev build or next release.
Context
SemoTech — self-hosted LogTide v1.3.2, Caddy WAN Geography dashboard (Vector → LogTide, GeoIP pipeline on
client_ip).We use Top-N table panels with
dimension: metadataand a flat key for ranked locations + hit counts (#299). v1.3.2 time-range picker (#305) works well. Thank you for shipping both.Today we work around two display gaps with a bind-mounted patch to
log-pipeline/steps/geoip.json backend + worker. We would rather drop the patch and use native behavior.Problem 1 —
geo_placeincludes coordinates in the human labelThe GeoIP step writes
geo_placeas:41.90,12.50|Rome, ItalyThat format is correct for geo_map points mode (single group-by key). For Top-N tables, operators want the label without lat/lon:
Rome, Italy(orRome, USA)We currently derive
geo_labelin our patch by stripping the coordinate prefix.Problem 2 — Top-N needs location and connection target in one dimension
Top-N panels accept a single metadata key. We want rows like:
New York, USA → host.domain.com - agentnot the full URL (
https://host.domain.com/agents/…), which explodes cardinality on agent heartbeats.Our patch adds
geo_hitbuilt from:City, USA)http_host,http_uri,hit_class,http_meaning), e.g.host.domain.com - agent|portal|blocked|websiteProposal
Extend the geoip pipeline step (or a small optional follow-on step) to emit:
geo_place40.72,-74.00|New York, United Statesgeo_labelNew York, USAgeo_hitNew York, USA → host.domain.com - agenthttp_hostpresent)Country shortening: optional locale/short-name map (
United States→USA,United Kingdom→UK) — config flag on the geoip step, default off for backward compatibility.Connection target: derive a low-cardinality role from request metadata already on the log (host + path class), not full URI. Suggested roles:
agent,portal,website,blocked,site(fallback). Could be a simple rules table in step config or sensible defaults.Why not multiple Top-N columns?
LogTide Top-N is one dimension today; composite string keeps one panel and matches Graylog-style “location + what they hit” summaries.
Our workaround today (for context only — not asking LogTide to support bind mounts)
Patch must be re-verified on every image upgrade. Native keys would remove this ops burden.
Acceptance ideas
geo_labelemitted by geoip step (coords stripped; optional short country names)geo_hitwhenhttp_host(and optionally path) exists in metadata at pipeline timegeo_place/ geo_map behaviorHappy to test on our WAN dashboard from a dev build or next release.