# Can't change index field mapping to geo\_ip

**URL:** <https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491>\
**Category:** Elasticsearch\
**Created:** [February 9, 2017, 12:10pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491 "2017-02-09T12:10:16Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 12:10pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/1 "2017-02-09T12:10:16Z")

</div>

Hi,

I'm trying to get Kibana tile map get working, basically I'm after changing geoip.location field type to geo\_ip . This is my index file:

{  
"fedora26-2017.02.09": {  
"aliases": {},  
"mappings": {  
"nginx-access": {  
"properties": {  
"@timestamp": {  
"type": "date",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
},  
"@version": {  
"type": "string"  
},  
"beat": {  
"properties": {  
"hostname": {  
"type": "string"  
},  
"name": {  
"type": "string"  
}  
}  
},  
"browserdevice": {  
"type": "string"  
},  
"browsermajor": {  
"type": "string"  
},  
"browserminor": {  
"type": "string"  
},  
"browsername": {  
"type": "string"  
},  
"browseros": {  
"type": "string"  
},  
"browseros\_name": {  
"type": "string"  
},  
"browserpatch": {  
"type": "string"  
},  
"count": {  
"type": "long"  
},  
"geoip": {  
"properties": {  
"area\_code": {  
"type": "long"  
},  
"city\_name": {  
"type": "string"  
},  
"continent\_code": {  
"type": "string"  
},  
"country\_code2": {  
"type": "string"  
},  
"country\_code3": {  
"type": "string"  
},  
"country\_name": {  
"type": "string"  
},  
"dma\_code": {  
"type": "long"  
},  
"ip": {  
"type": "string"  
},  
"latitude": {  
"type": "double"  
},  
"location": {  
"type": "double"  
},  
"longitude": {  
"type": "double"  
},  
"postal\_code": {  
"type": "string"  
},  
"real\_region\_name": {  
"type": "string"  
},  
"region\_name": {  
"type": "string"  
},  
"timezone": {  
"type": "string"  
}  
}  
},  
"input\_type": {  
"type": "string"  
},  
"offset": {  
"type": "long"  
},  
"our\_server": {  
"type": "string"  
},  
"referer": {  
"type": "string"  
},  
"request": {  
"type": "string"  
},  
"request\_arrival\_time": {  
"type": "string"  
},  
"request\_body\_bytes\_sent": {  
"type": "string"  
},  
"request\_ip": {  
"type": "string"  
},  
"request\_length": {  
"type": "string"  
},  
"request\_processing\_time": {  
"type": "string"  
},  
"request\_response\_code": {  
"type": "string"  
},  
"source": {  
"type": "string"  
},  
"tags": {  
"type": "string"  
},  
"type": {  
"type": "string"  
},  
"upstream\_response\_time": {  
"type": "string"  
},  
"user\_agent": {  
"type": "string"  
}  
}  
}  
},  
"settings": {  
"index": {  
"creation\_date": "1486636747483",  
"number\_of\_shards": "5",  
"number\_of\_replicas": "1",  
"uuid": "97bE3qj5QWqsckpbf0TnqA",  
"version": {  
"created": "2040499"  
}  
}  
},  
"warmers": {}  
}  
}

And this is how I'm changing it (via app sense):

PUT fedora26-2017.02.09  
{  
"mappings": {  
"nginx-access": {  
"properties": {  
"geoip": {  
"properties": {  
"location": {  
"type": "geo\_point"  
}  
}  
}  
}  
}  
}  
}

but getting this instead:  
{  
"error": {  
"root\_cause": [  
{  
"type": "index\_already\_exists\_exception",  
"reason": "already exists",  
"index": "fedora26-2017.02.09"  
}  
],  
"type": "index\_already\_exists\_exception",  
"reason": "already exists",  
"index": "fedora26-2017.02.09"  
},  
"status": 400  
}

So I'm not sure how to change field type here ? What exactly needs to be done ?

Thank you

---

<div class="post-metadata">

**Author:** ![wenpos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wenpos/32/15326_2.png) [@wenpos](https://discuss.elastic.co/u/wenpos)\
**Post date:** [February 9, 2017, 12:19pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/2 "2017-02-09T12:19:25Z")

</div>

this may give some suggestions:  
[https://www.elastic.co/guide/en/elasticsearch/reference/5.2/geo-point.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.2/geo-point.html)

---

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 12:21pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/3 "2017-02-09T12:21:59Z")

</div>

I've read that page already, there is nothing related to my problem.

---

<div class="post-metadata">

**Author:** ![wenpos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wenpos/32/15326_2.png) [@wenpos](https://discuss.elastic.co/u/wenpos)\
**Post date:** [February 9, 2017, 12:25pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/4 "2017-02-09T12:25:38Z")

</div>

The last EXCEPTION indicate an incorrect url to rebuild the existed index. how would you index on the mappings?

---

<div class="post-metadata">

**Author:** ![Matthew\_Bullock](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_bullock/32/47550_2.png) [@Matthew\_Bullock](https://discuss.elastic.co/u/Matthew_Bullock)\
**Post date:** [February 9, 2017, 1:25pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/5 "2017-02-09T13:25:59Z")

</div>

You are already defining your geoip in the first index creation you need to define the geo\_point within this.

"location": {  
"type": "double"

---

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 1:42pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/6 "2017-02-09T13:42:55Z")

</div>

Wenpos:

I'm not sure if I understand your question, I'm very new to elk, just trying to make tile map to work in kibana. So if you could please be more specific then I could try to answer..

Matthew:

I've tried to change from geo\_ip to double, but still getting this:  
{  
"error": {  
"root\_cause": [  
{  
"type": "index\_already\_exists\_exception",  
"reason": "already exists",  
"index": "fedora26-2017.02.09"  
}  
],  
"type": "index\_already\_exists\_exception",  
"reason": "already exists",  
"index": "fedora26-2017.02.09"  
},  
"status": 400  
}

---

<div class="post-metadata">

**Author:** ![kravigupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kravigupta/32/14811_2.png) [@kravigupta](https://discuss.elastic.co/u/kravigupta)\
**Post date:** [February 9, 2017, 2:07pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/7 "2017-02-09T14:07:59Z")

</div>

Try this -

PUT fedora26-2017.02.09/\_mappings/nginx-access  
{  
"properties": {  
"geoip": {  
"properties": {  
"location": {  
"type": "geo\_point"  
}  
}  
}  
}  
}

You should be calling \_mapping endpoint. Calling index name only will make it an index api call.

HTH

---

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 2:10pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/8 "2017-02-09T14:10:32Z")

</div>

Thanks Kravigupta.

I get this message now when I send your query:

{  
"error": {  
"root\_cause": [  
{  
"type": "illegal\_argument\_exception",  
"reason": "mapper [geoip.location] of different type, current\_type [double], merged\_type [geo\_point]"  
}  
],  
"type": "illegal\_argument\_exception",  
"reason": "mapper [geoip.location] of different type, current\_type [double], merged\_type [geo\_point]"  
},  
"status": 400  
}

---

<div class="post-metadata">

**Author:** ![kravigupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kravigupta/32/14811_2.png) [@kravigupta](https://discuss.elastic.co/u/kravigupta)\
**Post date:** [February 9, 2017, 2:24pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/9 "2017-02-09T14:24:00Z")

</div>

Create an scripted field using Kiban \> Index Patters \> Fedora\* \> Scripted fields.

name it geoip.location  
set value as  
[geoip.latitude,geoip.longitude]

If this does not give you any error, go for it and then do what I suggested earlier.

---

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 3:08pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/10 "2017-02-09T15:08:51Z")

</div>

Same problem.

But why exactly I'm getting that error ? I'm just trying to change field type to geo\_point but I can't find a way to do that ☹

---

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 3:35pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/11 "2017-02-09T15:35:49Z")

</div>

I'm trying to put nginx-access mapping like this using app sense:

PUT fedora26-2017.02.09/\_mappings/nginx-access  
{  
"fedora26-2017.02.09": {  
"mappings": {  
"nginx-access": {  
"properties": {  
"@timestamp": {  
"type": "date",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
},  
"@version": {  
"type": "string"  
},  
"beat": {  
"properties": {  
"hostname": {  
"type": "string"  
},  
"name": {  
"type": "string"  
}  
}  
},  
"browserdevice": {  
"type": "string"  
},  
"browsermajor": {  
"type": "string"  
},  
"browserminor": {  
"type": "string"  
},  
"browsername": {  
"type": "string"  
},  
"browseros": {  
"type": "string"  
},  
"browseros\_name": {  
"type": "string"  
},  
"browserpatch": {  
"type": "string"  
},  
"count": {  
"type": "long"  
},  
"geoip": {  
"properties": {  
"city\_name": {  
"type": "string"  
},  
"continent\_code": {  
"type": "string"  
},  
"country\_code2": {  
"type": "string"  
},  
"country\_code3": {  
"type": "string"  
},  
"country\_name": {  
"type": "string"  
},  
"ip": {  
"type": "string"  
},  
"latitude": {  
"type": "double"  
},  
"location": {  
"type": "double"  
},  
"longitude": {  
"type": "double"  
},  
"real\_region\_name": {  
"type": "string"  
},  
"region\_name": {  
"type": "string"  
},  
"timezone": {  
"type": "string"  
}  
}  
},  
"input\_type": {  
"type": "string"  
},  
"offset": {  
"type": "long"  
},  
"our\_server": {  
"type": "string"  
},  
"referer": {  
"type": "string"  
},  
"request": {  
"type": "string"  
},  
"request\_arrival\_time": {  
"type": "string"  
},  
"request\_body\_bytes\_sent": {  
"type": "string"  
},  
"request\_ip": {  
"type": "string"  
},  
"request\_length": {  
"type": "string"  
},  
"request\_processing\_time": {  
"type": "string"  
},  
"request\_response\_code": {  
"type": "string"  
},  
"source": {  
"type": "string"  
},  
"tags": {  
"type": "string"  
},  
"type": {  
"type": "string"  
},  
"upstream\_response\_time": {  
"type": "string"  
},  
"user\_agent": {  
"type": "string"  
}  
}  
}  
}  
}  
}

and in return I'm getting this:

{  
"error": {  
"root\_cause": [  
{  
"type": "mapper\_parsing\_exception",  
"reason": "Root mapping definition has unsupported parameters: [fedora26-2017.02.09 : {mappings={nginx-access={properties={@timestamp={type=date, format=strict\_date\_optional\_time||epoch\_millis}, @version={type=string}, beat={properties={hostname={type=string}, name={type=string}}}, browserdevice={type=string}, browsermajor={type=string}, browserminor={type=string}, browsername={type=string}, browseros={type=string}, browseros\_name={type=string}, browserpatch={type=string}, count={type=long}, geoip={properties={city\_name={type=string}, continent\_code={type=string}, country\_code2={type=string}, country\_code3={type=string}, country\_name={type=string}, ip={type=string}, latitude={type=double}, location={type=double}, longitude={type=double}, real\_region\_name={type=string}, region\_name={type=string}, timezone={type=string}}}, input\_type={type=string}, offset={type=long}, our\_server={type=string}, referer={type=string}, request={type=string}, request\_arrival\_time={type=string}, request\_body\_bytes\_sent={type=string}, request\_ip={type=string}, request\_length={type=string}, request\_processing\_time={type=string}, request\_response\_code={type=string}, source={type=string}, tags={type=string}, type={type=string}, upstream\_response\_time={type=string}, user\_agent={type=string}}}}}]"  
}  
],  
"type": "mapper\_parsing\_exception",  
"reason": "Root mapping definition has unsupported parameters: [fedora26-2017.02.09 : {mappings={nginx-access={properties={@timestamp={type=date, format=strict\_date\_optional\_time||epoch\_millis}, @version={type=string}, beat={properties={hostname={type=string}, name={type=string}}}, browserdevice={type=string}, browsermajor={type=string}, browserminor={type=string}, browsername={type=string}, browseros={type=string}, browseros\_name={type=string}, browserpatch={type=string}, count={type=long}, geoip={properties={city\_name={type=string}, continent\_code={type=string}, country\_code2={type=string}, country\_code3={type=string}, country\_name={type=string}, ip={type=string}, latitude={type=double}, location={type=double}, longitude={type=double}, real\_region\_name={type=string}, region\_name={type=string}, timezone={type=string}}}, input\_type={type=string}, offset={type=long}, our\_server={type=string}, referer={type=string}, request={type=string}, request\_arrival\_time={type=string}, request\_body\_bytes\_sent={type=string}, request\_ip={type=string}, request\_length={type=string}, request\_processing\_time={type=string}, request\_response\_code={type=string}, source={type=string}, tags={type=string}, type={type=string}, upstream\_response\_time={type=string}, user\_agent={type=string}}}}}]"  
},  
"status": 400  
}

Which is nothing else but old mapping data. So in other words , I can get mapping data extract, but if I'm trying to send it back to ELK - it fails, which makes no sense to me.

---

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 5:06pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/13 "2017-02-09T17:06:11Z")

</div>

Guys, I've cracked the issue, please mark it as closed.

Thank you for those who helped.

---

<div class="post-metadata">

**Author:** ![kravigupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kravigupta/32/14811_2.png) [@kravigupta](https://discuss.elastic.co/u/kravigupta)\
**Post date:** [February 9, 2017, 5:07pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/14 "2017-02-09T17:07:12Z")

</div>

Jonasv, it would help for others if you could post the solution. 🙂

---

<div class="post-metadata">

**Author:** ![jonasv](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jonasv](https://discuss.elastic.co/u/jonasv)\
**Post date:** [February 9, 2017, 5:44pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/15 "2017-02-09T17:44:39Z")

</div>

Sure.

If you have a look what I was doing here:

PUT fedora26-2017.02.09/\_mappings/nginx-access  
{  
"fedora26-2017.02.09": {  
"mappings": {  
"nginx-access": {  
"properties": {  
"@timestamp": {  
"type": "date",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
...

So I was sending that payload to fedora26-2017.02.09/\_mappings/nginx-access , but correct way is to delete  
{  
"fedora26-2017.02.09": {  
"mappings": {  
"nginx-access": {

and then send to fedora26-2017.02.09/\_mappings/nginx-access

Also, it took me a while to find a simple sentence somewhere that once the data is in - you can't change existing index or mapping. So in real world - you create index structure and mapping (for example through kibana appsense) and then you load the data. I wish these words were somewhere in manual at the beginning, but unfortunately it is one big mess in my eyes. It is good and valuable if you need to read about some function (for example about grok or mutate - it is perfect), but if you are very new to ELK and such kind of search systems - there is no value in manual, better read tutorials and look for answers outside the scope of this website, anyway, it is just my opinion and ELK technology is not the easiest thing you can learn.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2017, 5:44pm UTC](https://discuss.elastic.co/t/cant-change-index-field-mapping-to-geo-ip/74491/16 "2017-03-09T17:44:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
