---
title: "Looking up GeoIP2 data from IP addresses"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-enrich-data/geoip2-parser/"
last_modified: "2026-08-05T13:24:59+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Looking up GeoIP2 data from IP addresses

The AxoSyslog application can lookup IP addresses from an offline GeoIP2 database, and make the retrieved data available in name-value pairs. Depending on the database used, you can access country code, longitude, and latitude information and so on.

The AxoSyslog application works with the Country and the City version of the GeoIP2 database, both free and the commercial editions. The AxoSyslog application works with the `mmdb` (GeoIP2) format of these databases. Other formats, like `csv` are not supported.

## Prerequisites

This feature requires a separate module. Install the `axosyslog-mod-geoip2` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-geoip` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

## Download the GeoIP2 database

> **Note:**
>
> To access longitude and latitude information, download the City version of the [GeoIP2](https://www.maxmind.com/en/geoip2-databases) database.
>
> There are two types of GeoIP2 databases available.
>
> - *GeoLite2 City:*
>
>   - free of charge
>   - less accurate
> - *GeoIP2 City:*
>
>   - has to be purchased
>   - more accurate
>
> Unzip the downloaded database (for example, to the `/usr/share/GeoIP2/GeoIP2City.mmdb` file). This path will be used later in the configuration.
>
> Starting with version 3.24, AxoSyslog tries to automatically detect the location of the database. If that is successful, the `database()` option is not mandatory.

---

[Referring to parts of the message as a macro](https://axoflow.com/docs/axosyslog-core/4.28/chapter-enrich-data/geoip2-parser/referring-to-parts-of-the-message-as-a-macro/index.md)

[Using the GeoIP2 parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-enrich-data/geoip2-parser/using-the-geoip2-parser/index.md)

[Transferring your logs to Elasticsearch using GeoIP2](https://axoflow.com/docs/axosyslog-core/4.28/chapter-enrich-data/geoip2-parser/transferring-your-logs-to-elasticsearch-using-geoip2/index.md)

[Options of geoip2 parsers](https://axoflow.com/docs/axosyslog-core/4.28/chapter-enrich-data/geoip2-parser/geoip2-parser-options/index.md)

Last modified August 5, 2026: [Adds required packages to template functions and data enrichment (804f1f2f)](https://github.com/axoflow/axosyslog-core-docs/commit/804f1f2ff9003aaceaede20ed933921cec1c890f)
