# Building a Tile Map in Kibana

**URL:** <https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483>\
**Category:** Kibana\
**Created:** [April 26, 2016, 9:33pm UTC](https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483 "2016-04-26T21:33:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)\
**Post date:** [April 26, 2016, 9:33pm UTC](https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483/1 "2016-04-26T21:33:20Z")

</div>

I'm very new to this. I have an log file that I parsed into

```
 match => [
         "message", "%{SYSLOGTIMESTAMP:timestamp} %{IPORHOST:logsource}( *)Login Success: \[%{NOTSPACE:user}\] \(%{IP:client_ip}:%{POSINT:client_port}\)]
 geoip {
         source => "client_ip"
         target => "geoip"
         add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
         add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
 }
 mutate {
         convert => ["[geoip][coordinates]", "float"]
 }

```

The client\_ip field holds the IP address that I want to build a Tile Map with. I followed this blog (which I'm now thinking is out-of-date and incorrect) [https://www.digitalocean.com/community/tutorials/how-to-map-user-location-with-geoip-and-elk-elasticsearch-logstash-and-kibana](https://www.digitalocean.com/community/tutorials/how-to-map-user-location-with-geoip-and-elk-elasticsearch-logstash-and-kibana).

Then, in Sense I mapped the geoip.location field to geo\_point by running this:

```
PUT connect-log
{
    "mappings": {
      "connect-log": {
        "properties": {
          "geoip": {
            "properties" : {
              "location": {
                "type": "geo_point",
                "doc_values": true
              }  
            }
          }
        }
      }
    }
}

```

I think this worked because now I see this:

`GET connect-log/_mapping/connect-log/field/geoip.location`

```
{
  "connect-log": {
    "mappings": {
      "connect-log": {
        "geoip.location": {
          "full_name": "geoip.location",
          "mapping": {
            "location": {
              "type": "geo_point"
            }
          }
        }
      }
    }
  }
}

```

When I go to create a Tile Map visualization it detects that geoip.location is the right field to use, but it always says "No results found".

There seem to be 100's of topics with the same theme already, but it's all very convoluted especially to me!

Thanks in advance,  
Ryan

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 27, 2016, 5:36am UTC](https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483/2 "2016-04-27T05:36:36Z")

</div>

You have `geoip.location` in your mappings, but your LS config has `geoip.coordinates`, that's why 🙂

---

<div class="post-metadata">

**Author:** ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)\
**Post date:** [April 27, 2016, 4:39pm UTC](https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483/3 "2016-04-27T16:39:42Z")

</div>

Thanks for the reply, I'll try changing coordinates to location. But in kibana when I look at one of the log entries I see the same value for both geoip.location and geoip.coordinates. Honestly I don't know how location gets there in the first place haha.

Here's an example of the geoip entries for one log (as seen from Kibana):

> ```
> # geoip.area_code ###
> t geoip.city_name Franklin
> t geoip.continent_code NA
> # geoip.coordinates -xx.xxx, yy.yyy
> t geoip.country_code2 US
> t geoip.country_code3 USA
> t geoip.country_name United States
> # geoip.dma_code ###
> t geoip.ip xx.xx.xx.xx
> # geoip.latitude yy.yyy
> # geoip.location -xx.xxx, yy.yyy
> # geoip.longitude -xx.xxx
> t geoip.postal_code abcde
> t geoip.real_region_name	Massachusetts
> t geoip.region_name MA
> t geoip.timezone America/New_York
> 
> ```

EDIT:  
I tried changing "coordinates" to "location" in my logstash config, now the geoip.location field ends up with duplicate values:

`# geoip.location -xxx.xx, yyy.yy, -xxx.xx, yyy.yy`

---

<div class="post-metadata">

**Author:** ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)\
**Post date:** [April 28, 2016, 4:47pm UTC](https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483/4 "2016-04-28T16:47:05Z")

</div>

I got the Tile map working by reassigning the geoip.location field to one that's not nested (mylocation). I have no idea why this mattered but it seems to be working now.

```
    geoip {
            source => "client_ip"
            target => "geoip"
            database => "/etc/logstash/GeoLiteCity.dat"
            add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
            add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
            add_field => ["mylocation", "%{[geoip][location]}" ]
    }

```

Thanks for the replies,  
Ryan

---

<div class="post-metadata">

**Author:** ![lucaiovio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucaiovio/32/496_2.png) [@lucaiovio](https://discuss.elastic.co/u/lucaiovio)\
**Post date:** [June 8, 2016, 12:45pm UTC](https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483/5 "2016-06-08T12:45:12Z")

</div>

Hi Ryan.

I know you've already solved this topic, but I'm experiencing the same problem. Can you clarify if following steps are correct?

1 - configure logstash with a new field during geoip filter:  
(...)  
add\_field =\> ["mylocation", "%{[geoip][location]}" ]  
(...)

2 - run logstash import

3 - apply mapping for geo\_point to the same index userd with logstash import

PUT connect-log  
{  
"mappings": {  
"connect-log": {  
"properties": {  
"mylocation": {  
"type": "geo\_point",  
"doc\_values": true  
}  
}  
}  
}  
}

4 - configure index in kibana; mylocation field must be type geo\_point.

5 - create tile map visualization

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:51pm UTC](https://discuss.elastic.co/t/building-a-tile-map-in-kibana/48483/6 "2017-07-06T13:51:10Z")

</div>


