# Convert string LLA to Geo-Point

**URL:** <https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376>\
**Category:** Logstash\
**Created:** [January 18, 2024, 6:49pm UTC](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376 "2024-01-18T18:49:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael\_c\_michael](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Post date:** [January 18, 2024, 6:49pm UTC](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376/1 "2024-01-18T18:49:13Z")

</div>

I have a string field that is in Latitude, Longitude, Altitude. In the pipeline, I am taking the location in x, y, z in ECEF coordinates and converting to LLA:

```auto
    - pipeline.id: entity-state-processing
      config.string: |
        input { pipeline { address => entitystatelogs } }
        filter {
          # Checks if the log has locational data before processing it into WGS 84 lat/long
          if [attributes][entityLocation] {
            mutate {
              add_field => {
              "[location]" => "null"
            }
          }

          # Ruby script to convert the cartesian x,y,z coordinates into lat/long
          ruby {
            init => "
              R = 6360000
              "
            code => "
              x = event.get('[attributes][entityLocation][x]').to_f
              y = event.get('[attributes][entityLocation][y]').to_f
              z = event.get('[attributes][entityLocation][z]').to_f

              range = Math.sqrt(x*x + y*y + z*z)

              lat = 180*Math.asin(z/range)/Math::PI
              long = 180*Math.atan2(y,x)/Math::PI
              alt = range - 6369783.457722581

              event.set('[location]', lat.to_s + ',' + long.to_s, + ',' + alt.to_s)
              "
              }
            }
          }
        output {
          # Sends parsed logs to elasticsearch
          elasticsearch {
            hosts => ["${OUTPUT_HOST}"]
            user => "${ELASTIC_USER}"
            password => "${ELASTIC_PASS}"
            index => "{{ .Release.Namespace }}-entity-state-%{+yyyy.MM.dd}"
            }
        }

```

So, in ELK, location is a string that looks like: (12.5, 50, 1000). Is there a way to convert this to a geo-point inside the pipeline? Do I have to use a template. If so, how is that done?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 18, 2024, 6:55pm UTC](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376/2 "2024-01-18T18:55:18Z")

</div>

> [@michael\_c\_michael](#):
>
> Is there a way to convert this to a geo-point inside the pipeline?

logstash has no concept of a geo\_point. If you have created a field in elasticsearch that is mapped as a geo\_point (using a template) then elasticsearch will parse several formats, including a string "12.5, 50". This is documented [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html). It includes an example of how to set the template.

---

<div class="post-metadata">

**Author:** ![michael\_c\_michael](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Post date:** [January 18, 2024, 7:38pm UTC](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376/3 "2024-01-18T19:38:36Z")

</div>

I don't see how this explains how to do so using a template.

It also doesn't show that the geo-point converts strings of the format (12, 50, 100).

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 18, 2024, 7:47pm UTC](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376/4 "2024-01-18T19:47:14Z")

</div>

> [@michael\_c\_michael](#):
>
> It also doesn't show that the geo-point converts strings of the format (12, 50, 100).

Geo-point fields in Elasticsearch are latitude and longitude only, there is no altitude, so you need to transform your field to remove the altitude value _before_ sending the data to Elastisearch.

The documentation linked has some examples on how the value of a location field should be.

So you would need to edit your ruby script to remove the altitude value and use the latitude and longitude value on one of the supported formats, like for example `location: "lat, lon"`.

Also, for a field to work as a geo\_point, you need to map it first, before sending any data, this can be done as the example in the documentation linked or using an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html) with this mapping.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2024, 7:47pm UTC](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376/5 "2024-02-15T19:47:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
