Problem
Geo-location (GeoIP) information is missing in the indexed FortiGate logs.
In Kibana (Data view: logs-fortinet.fortigate*), I can see and use:
fgt.dstcountry
fgt.srccountry
…but there are no geo location fields available (searching geo returns no matching fields), so I can’t use Maps / geo aggregations.
Environment
- ELK / Elastic Stack: 9.2.1
- Integration / pipeline: fortinet-2-elasticsearch

Problem
Geo-location (GeoIP) information is missing in the indexed FortiGate logs.
In Kibana (Data view:
logs-fortinet.fortigate*), I can see and use:fgt.dstcountryfgt.srccountry…but there are no geo location fields available (searching
georeturns no matching fields), so I can’t use Maps / geo aggregations.Environment