# Adding additional geo\_point fields

**URL:** <https://discuss.elastic.co/t/adding-additional-geo-point-fields/162184>\
**Category:** Logstash\
**Created:** [December 26, 2018, 11:23pm UTC](https://discuss.elastic.co/t/adding-additional-geo-point-fields/162184 "2018-12-26T23:23:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kenneth\_M\_Kolano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenneth_m_kolano/32/38752_2.png) [@Kenneth\_M\_Kolano](https://discuss.elastic.co/u/Kenneth_M_Kolano)\
**Post date:** [December 26, 2018, 11:23pm UTC](https://discuss.elastic.co/t/adding-additional-geo-point-fields/162184/1 "2018-12-26T23:23:12Z")

</div>

Hoping someone can assist with where I'm going wrong with adding two additional geoip/geo\_point fields. I've updated each of the default templates on Ubuntu to include the additional points, duplicating the pre-existing geoip config...

/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.2.4-java/lib/logstash/outputs/elasticsearch/elasticsearch-template-es6x.json

```
{
  "template": "logstash-*",
  "version": 60001,
  "settings": {
    "index.refresh_interval": "5s"
  },
  "mappings": {
    "_default_": {
      "dynamic_templates": [
        {
          "message_field": {
            "path_match": "message",
            "match_mapping_type": "string",
            "mapping": {
              "type": "text",
              "norms": false
            }
          }
        },
        {
          "string_fields": {
            "match": "*",
            "match_mapping_type": "string",
            "mapping": {
              "type": "text",
              "norms": false,
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            }
          }
        }
      ],
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "keyword"
        },
        "geoip": {
          "dynamic": true,
          "properties": {
            "ip": {
              "type": "ip"
            },
            "location": {
              "type": "geo_point"
            },
            "latitude": {
              "type": "half_float"
            },
            "longitude": {
              "type": "half_float"
            }
          }
        },
        "src_geoip": {
          "dynamic": true,
          "properties": {
            "ip": {
              "type": "ip"
            },
            "location": {
              "type": "geo_point"
            },
            "latitude": {
              "type": "half_float"
            },
            "longitude": {
              "type": "half_float"
            }
          }
        },
        "dest_geoip": {
          "dynamic": true,
          "properties": {
            "ip": {
              "type": "ip"
            },
            "location": {
              "type": "geo_point"
            },
            "latitude": {
              "type": "half_float"
            },
            "longitude": {
              "type": "half_float"
            }
          }
        }
      }
    }
  }
}

```

But when using the logstash geoip plugin to populate them...

```
geoip {
   source => "src_ip"
   target => "src_geoip"
   fields => ["city_name", "continent_code", "country_code2", "country_name", "latitude", "longitude", "location", "postal_code", "region_name", "timezone"]
   database => "/usr/share/GeoIP/GeoLite2-City.mmdb"
   tag_on_failure => "_src_geoip_failure"
}

```

I get two separate properties rather than a geo\_point...  
src\_geoip.location.lat: xx.xxx  
src\_geoip.location.lon : xx.xxx

Looking at my indexes default mappings:  
`/logstash-*/_mapping/_default_`  
...it doesn't appear that the properties I added came over.

```
{
  "logstash-2018.12.26.23" : {
    "mappings" : {
      "_default_" : {
        "dynamic_templates" : [
          {
            "message_field" : {
              "path_match" : "message",
              "match_mapping_type" : "string",
              "mapping" : {
                "norms" : false,
                "type" : "text"
              }
            }
          },
          {
            "string_fields" : {
              "match" : "*",
              "match_mapping_type" : "string",
              "mapping" : {
                "fields" : {
                  "keyword" : {
                    "ignore_above" : 256,
                    "type" : "keyword"
                  }
                },
                "norms" : false,
                "type" : "text"
              }
            }
          }
        ],
        "properties" : {
          "@timestamp" : {
            "type" : "date"
          },
          "@version" : {
            "type" : "keyword"
          },
          "geoip" : {
            "dynamic" : "true",
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "location" : {
                "type" : "geo_point"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          }
        }
      }
    }
  }
}

```

It also feels weird poking at those deeply nested config files just to add a geo\_point, but that's been indicated in forum posts and I can't find specific documentation on such.

- [https://www.elastic.co/blog/geoip-in-the-elastic-stack](https://www.elastic.co/blog/geoip-in-the-elastic-stack) : talks about the default template but fails to provide details relevant to updating it
- [https://www.elastic.co/blog/logstash\_lesson\_elasticsearch\_mapping](https://www.elastic.co/blog/logstash_lesson_elasticsearch_mapping) : provides template update details, but not for the default templates; I'm confused how I can define a template by upload like that. since I need to have an index to upload into, and when I have an index it will already have loaded data with the wrong template.

---

<div class="post-metadata">

**Author:** ![Kenneth\_M\_Kolano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenneth_m_kolano/32/38752_2.png) [@Kenneth\_M\_Kolano](https://discuss.elastic.co/u/Kenneth_M_Kolano)\
**Post date:** [December 27, 2018, 4:16pm UTC](https://discuss.elastic.co/t/adding-additional-geo-point-fields/162184/2 "2018-12-27T16:16:07Z")

</div>

I'm guessing that the defaults from the config files aren't actually used once ES has been installed. I had presumed they would be if edited prior to it's initial startup.

I tried adding the template to my logstash output config...

```
output {
	elasticsearch {
		hosts => localhost
		index => "logstash-%{+YYYY.MM.dd.HH}"
		template => "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.2.4-java/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json"
	}
}

```

...but I'm still not seeing the appropriate default template on the created indexes.

---

<div class="post-metadata">

**Author:** ![Kenneth\_M\_Kolano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenneth_m_kolano/32/38752_2.png) [@Kenneth\_M\_Kolano](https://discuss.elastic.co/u/Kenneth_M_Kolano)\
**Post date:** [December 27, 2018, 6:40pm UTC](https://discuss.elastic.co/t/adding-additional-geo-point-fields/162184/3 "2018-12-27T18:40:35Z")

</div>

I needed to update the default logstash template in ES, not the one in the config file: /\_template/logstash/

```
{
  "logstash" : {
    "order" : 0,
    "version" : 60001,
    "index_patterns" : [
      "logstash-*"
    ],
    "settings" : {
      "index" : {
        "refresh_interval" : "5s"
      }
    },
    "mappings" : {
      "_default_" : {
        "dynamic_templates" : [
          {
            "message_field" : {
              "path_match" : "message",
              "match_mapping_type" : "string",
              "mapping" : {
                "type" : "text",
                "norms" : false
              }
            }
          },
          {
            "string_fields" : {
              "match" : "*",
              "match_mapping_type" : "string",
              "mapping" : {
                "type" : "text",
                "norms" : false,
                "fields" : {
                  "keyword" : {
                    "type" : "keyword",
                    "ignore_above" : 256
                  }
                }
              }
            }
          }
        ],
        "properties" : {
          "@timestamp" : {
            "type" : "date"
          },
          "@version" : {
            "type" : "keyword"
          },
          "geoip" : {
            "dynamic" : true,
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "location" : {
                "type" : "geo_point"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "src_geoip" : {
            "dynamic" : true,
            "properties" : {
              "location" : {
                "type" : "geo_point"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "dest_geoip" : {
            "dynamic" : true,
            "properties" : {
              "location" : {
                "type" : "geo_point"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          }
        }
      }
    },
    "aliases" : { }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2019, 7:05pm UTC](https://discuss.elastic.co/t/adding-additional-geo-point-fields/162184/5 "2019-01-24T19:05:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
