# Converting to geo\_point

**URL:** <https://discuss.elastic.co/t/converting-to-geo-point/125417>\
**Category:** Logstash\
**Created:** [March 23, 2018, 10:51pm UTC](https://discuss.elastic.co/t/converting-to-geo-point/125417 "2018-03-23T22:51:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pororo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pororo/32/27711_2.png) [@Pororo](https://discuss.elastic.co/u/Pororo)\
**Post date:** [March 23, 2018, 10:51pm UTC](https://discuss.elastic.co/t/converting-to-geo-point/125417/1 "2018-03-23T22:51:48Z")

</div>

Hi,

For now, I have my own fields called "lat" and "lon" in the json file.

I was trying to make ES recognize it as the geo\_point data so I did some kinds of editing in Logstash.

```
filter {
	mutate{
		add_field => {"location" => [[lat],[lon]]}
	}
}

```

But it turned out that the type of geoip.location is not geo\_point.

I am wondering if there is something wrong with my filter?

Updated: the logstash threw me the error like this

```
[2018-03-23T20:04:37,029][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"locationdata", :_type=>"eventdata", :_routing=>nil}, #<LogStash::Event:0x6bfc6277>], :response=>{"index"=>{"_index"=>"locationdata", "_type"=>"eventdata", "_id"=>"XNFSVWIB-SahT3BDQlYN", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"illegal latitude value [269.9986267089844] for location"}}}}}
{
              "lon" => 25,
       "@timestamp" => 2018-03-24T00:04:36.649Z,
             "host" => "appletekiMacBook-Pro.local",
         "@version" => "1",
              "lat" => 15,
    "location_info" => "united/michigan:[15,25]",
         "location" => [
        [0] "[\"lat\"]",
        [1] "[\"lon\"]"
    ],
             "path" => "/Users/apple/Desktop/Location/location.json"
}
```

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 24, 2018, 7:04am UTC](https://discuss.elastic.co/t/converting-to-geo-point/125417/2 "2018-03-24T07:04:59Z")

</div>

There are a number of accepted forms for [geo\_point](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html); I believe you were going with the two-element array variant (e.g., `[12.34, 56.78]`), but it ends up being easier to use the object variant (e.g., `{"lat": 12.34, "lon": 56.78}`).

* * *

Since the `add_field` directive can only add _string_ values, if we wanted to use it we would need to do some extra work to convert the values back to numeric values; instead, we can use `rename` to _move_ both values (or `copy` to copy them and leave the previous fields in-tact)

```auto
filter {
  mutate {
    rename => {
      "lat" => "[location][lat]"
      "lon" => "[location][lon]"
    }
  }
}

```

OR

```auto
filter {
  mutate {
    copy => {
      "lat" => "[location][lat]"
      "lon" => "[location][lon]"
    }
  }
}

```

* * *

If you _do_ need the two-element-array syntax for some reason (it makes no difference to Elasticsearch which one we use as long as the field is defined as a `geo_point` in the index mapping), we would have to change it up a bit.

The syntax `[[lat],[lon]]` that you have isn't quite right to get us there; it parses out to mean

- an array, containing:
  - an array, containing the literal string `lat`; AND
  - an array, containing the literal string `lon`

Instead, we need to add a two-element array, containing the value-at-`[lat]` and the value-at-`[lon]`, and since this produces strings, we would need to convert them back to floating-point numbers:

```auto
filter {
  mutate {
    add_field => {
      "location" => ["%{[lat]}","%{[lon]}"]
    }
  }
  mutate {
    convert => {
      "location" => "float"
    }
  }
}

```

* * *

For good measure, if we wanted the string variant, it would be pretty easy too:

```auto
filter {
  mutate {
    add_field => {
      "location" => "%{lat},%{lon}"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Pororo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pororo/32/27711_2.png) [@Pororo](https://discuss.elastic.co/u/Pororo)\
**Post date:** [March 27, 2018, 2:22am UTC](https://discuss.elastic.co/t/converting-to-geo-point/125417/3 "2018-03-27T02:22:42Z")

</div>

Thank you so much. Your demonstration helped me a lot.

I have some questions tho. The first is if I just used your last method, ES will recognize "location" as the type of string. So do I need to set the mapping for this data to specify the type of "location" should be geo\_point in the console of kibana in advance? I am kinda confused cuz I thought ES will automatically do the recognizion.

For getting the value of the field, you mentioned using %{[lat]}. I am wondering if it works for the case that I want to parse something from the specific field which is in the original input data.

Or could you take a look at [Geo point mapping](https://discuss.elastic.co/t/geo-point-mapping/125105)

Thanks again!!!

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 29, 2018, 5:13pm UTC](https://discuss.elastic.co/t/converting-to-geo-point/125417/4 "2018-03-29T17:13:55Z")

</div>

yes, it is advised to set up the index mapping, either explicitly or via a template.

Any time we make a computer "guess" a best fit, we run the risk of it guessing incorrectly, so it's best to be explicit wherever possible.

> [@Pororo](#):
>
> For getting the value of the field, you mentioned using %{[lat]}. I am wondering if it works for the case that I want to parse something from the specific field which is in the original input data.

The `add_field` directive, and many others, allow us to reference existing fields from the event by name using what is called [sprintf notation](https://www.elastic.co/guide/en/logstash/6.2/event-dependent-configuration.html#sprintf); not all directives support it, so you'll need to rely on documentation for the particular plugin and/or experimentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2018, 5:14pm UTC](https://discuss.elastic.co/t/converting-to-geo-point/125417/5 "2018-04-26T17:14:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
