# Could not able to use geo\_ip in logstash 2.4

**URL:** <https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689>\
**Category:** Logstash\
**Created:** [October 23, 2016, 5:17pm UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689 "2016-10-23T17:17:44Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kim\_Daniel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kim_daniel/32/12663_2.png) [@Kim\_Daniel](https://discuss.elastic.co/u/Kim_Daniel)\
**Post date:** [October 23, 2016, 5:17pm UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/1 "2016-10-23T17:17:44Z")

</div>

hi all,  
I'm trying to use geoip from apache access log with logstash 2.4, elasticsearch 2.4, kibna 4.6.

my logstash filter is...

input {  
file {  
path =\> "/var/log/httpd/access\_log"  
type =\> "apache"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\>"/home/elk/logstash-2.4.0/GeoLiteCity.dat"  
#add\_field =\> { "foo\_%{somefield}" =\> "Hello world, from %{host}" }  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch  
{ hosts =\> ["192.168.56.200:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "apache-geoip-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

And if elasticsearch parsing some apache access log, the output is...

{  
"message" =\> "[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx) [24/Oct/2016:14:46:30 +0900] HTTP/1.1 8197 /images/egovframework/com/cmm/er\_logo.jpg 200",  
"@version" =\> "1",  
"@timestamp" =\> "2016-10-24T05:46:34.505Z",  
"path" =\> "/NCIALOG/JBOSS/SMBA/default-host/access\_log.2016-10-24",  
"host" =\> "smba",  
"type" =\> "jboss\_access\_log",  
"clientip" =\> "[xxx.xxxx.xxx.xxx](http://xxx.xxxx.xxx.xxx)",  
"geoip" =\> {  
"ip" =\> "[xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx)",  
"country\_code2" =\> "KR",  
"country\_code3" =\> "KOR",  
"country\_name" =\> "Korea, Republic of",  
"continent\_code" =\> "AS",  
"region\_name" =\> "11",  
"city\_name" =\> "Seoul",  
"latitude" =\> xx.5985,  
"longitude" =\> xxx.97829999999999,  
"timezone" =\> "Asia/Seoul",  
"real\_region\_name" =\> "Seoul-t'ukpyolsi",  
"location" =\> [  
[0] xxx.97829999999999,  
[1] xx.5985  
],  
"coordinates" =\> [  
[0] xxx.97829999999999,  
[1] xx.5985  
]  
}  
}

When I create tile map with above filter I got this error in kibana web,  
"index pattern does not contain any of the following field types: geo\_point "

I could not able to see geo\_ip field.

please help me.  
Thanks.  
Daniel.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 1:51pm UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/2 "2016-10-24T13:51:21Z")

</div>

The default index template that ships with Logstash assumes that your index names match logstash-\*. Since you've renamed your indexes you have to install a matching index template (or just accept the default index name).

---

<div class="post-metadata">

**Author:** ![Kim\_Daniel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kim_daniel/32/12663_2.png) [@Kim\_Daniel](https://discuss.elastic.co/u/Kim_Daniel)\
**Post date:** [October 25, 2016, 12:15am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/3 "2016-10-25T00:15:02Z")

</div>

Hi magnusbaeck,

I chnaged my index name from jboss-access\* to logstash-\*. but result is same.

[grkim@smba ~]$ curl [http://192.168.0.50:9200/logstash\*/\_mapping?pretty](http://192.168.0.50:9200/logstash*/_mapping?pretty)  
{  
"logstash-2016.10" : {  
"mappings" : {  
"event" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "strict\_date\_optional\_time||epoch\_millis"  
},  
"@version" : {  
"type" : "string"  
},  
"clientip" : {  
"type" : "string"  
},  
"geoip" : {  
"properties" : {  
"city\_name" : {  
"type" : "string"  
},  
"continent\_code" : {  
"type" : "string"  
},  
"country\_code2" : {  
"type" : "string"  
},  
"country\_code3" : {  
"type" : "string"  
},  
"country\_name" : {  
"type" : "string"  
},  
"ip" : {  
"type" : "string"  
},  
"latitude" : {  
"type" : "double"  
},  
"location" : {  
"type" : "double"  
},  
"longitude" : {  
"type" : "double"  
},  
"real\_region\_name" : {  
"type" : "string"  
},  
"region\_name" : {  
"type" : "string"  
},  
"timezone" : {  
"type" : "string"  
}  
}  
},  
"host" : {  
"type" : "string"  
},  
"message" : {  
"type" : "string"  
},  
"path" : {  
"type" : "string"  
},  
"received\_at" : {  
"type" : "date",  
"format" : "strict\_date\_optional\_time||epoch\_millis"  
},  
"received\_from" : {  
"type" : "string"  
},  
"syslog\_facility" : {  
"type" : "string"  
},  
"syslog\_facility\_code" : {  
"type" : "long"  
},  
"syslog\_hostname" : {  
"type" : "string"  
},  
"syslog\_message" : {  
"type" : "string"  
},  
"syslog\_pid" : {  
"type" : "string"  
},  
"syslog\_program" : {  
"type" : "string"  
},  
"syslog\_severity" : {  
"type" : "string"  
},  
"syslog\_severity\_code" : {  
"type" : "long"  
},  
"syslog\_timestamp" : {  
"type" : "string"  
},  
"tags" : {  
"type" : "string"  
},  
"type" : {  
"type" : "string"  
}  
}  
}  
}  
}  
}

Am I missing some configuration?

Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 25, 2016, 3:06am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/4 "2016-10-25T03:06:56Z")

</div>

> [@Kim\_Daniel](#):
>
> manage\_template =\> false

It is possible that the index template for the `logstash-*` index is not getting applied as you have disabled this in the Elasticsearch output.

---

<div class="post-metadata">

**Author:** ![Kim\_Daniel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kim_daniel/32/12663_2.png) [@Kim\_Daniel](https://discuss.elastic.co/u/Kim_Daniel)\
**Post date:** [October 25, 2016, 4:56am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/5 "2016-10-25T04:56:54Z")

</div>

Hi Christian,

Thanks for your replay.  
Unfortunately it not working for me 😫  
The results are same.

---

<div class="post-metadata">

**Author:** ![Kim\_Daniel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kim_daniel/32/12663_2.png) [@Kim\_Daniel](https://discuss.elastic.co/u/Kim_Daniel)\
**Post date:** [October 25, 2016, 5:16am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/6 "2016-10-25T05:16:25Z")

</div>

I removed other option in my output configuration like this:

output {  
stdout { codec =\> rubydebug }  
elasticsearch  
{ hosts =\> ['192.168.0.50:9200']  
manage\_template =\> true  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}

I can see geo\_location when i execute " curl [http://192.168.0.50:9200/logstash\*/\_mapping?pretty](http://192.168.0.50:9200/logstash*/_mapping?pretty)" . but still could not able to use map in kibana.  
The error message from kibana is ..

" The "logstash-\*" index pattern does not contain any of the following field types: geo\_point "

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/80660f3cdda540850280a05a1771f945536aea88.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 25, 2016, 5:31am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/7 "2016-10-25T05:31:23Z")

</div>

Have you refreshed the field list in Kibana?

---

<div class="post-metadata">

**Author:** ![Kim\_Daniel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kim_daniel/32/12663_2.png) [@Kim\_Daniel](https://discuss.elastic.co/u/Kim_Daniel)\
**Post date:** [October 26, 2016, 12:34am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/8 "2016-10-26T00:34:49Z")

</div>

Hi magnusbaeck,

I refresed it. I got new mapping conflict warning message. I don't know why... and still I have same situation.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/5/59cc56ccc9d4986a5df7e7fe447b6cead864363e.png)

This is my new logstash configuration for my jboss access log ...

input {  
file {  
path =\> '/NCIALOG/JBOSS/SMBA/default-host/access\_log.\*'  
type =\> 'jboss\_access\_log'  
start\_position =\> 'beginning'  
}  
}

filter {  
if [type] == 'jboss\_access\_log' {  
grok {  
# 192.168.0.21 [24/Oct/2016:08:34:59 +0900] HTTP/1.1 7130 /boffice/sy/menu/MgrMenuListAx.do 200  
match =\> { 'message' =\> '%{IP:clientip}' }  
}  
geoip {  
source =\> 'clientip'  
add\_tag =\> ['GeoIP']  
database =\> '/home/elk/logstash-2.4.0/GeoLiteCity.dat'  
add\_field =\> ['[geoip][coordinates]', '%{[geoip][longitude]}' ]  
add\_field =\> ['[geoip][coordinates]', '%{[geoip][latitude]}' ]  
}  
mutate {  
convert =\> ['[geoip][coordinates]', 'float']  
}  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch  
{ hosts =\> ['192.168.0.50:9200']  
manage\_template =\> true  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 26, 2016, 5:30am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/9 "2016-10-26T05:30:39Z")

</div>

> I got new mapping conflict warning message. I don't know why...

Some of your indexes have geoip.location as a geo\_point and some have them as double.

> and still I have same situation.

Kibana _still_ complains about there not being any geo\_point fields even though everything indicates that geoip.location is a geo\_point? Okay, I give up. Ask about this in the Kibana category. Just double-check with the get mapping API that geoip.location really is a geo\_point for the most recent index.

---

<div class="post-metadata">

**Author:** ![Kim\_Daniel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kim_daniel/32/12663_2.png) [@Kim\_Daniel](https://discuss.elastic.co/u/Kim_Daniel)\
**Post date:** [October 26, 2016, 5:47am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/10 "2016-10-26T05:47:14Z")

</div>

hi magnusbaeck,

Thanks for your help. I'll do that.

Thanks.

---

<div class="post-metadata">

**Author:** ![Kim\_Daniel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kim_daniel/32/12663_2.png) [@Kim\_Daniel](https://discuss.elastic.co/u/Kim_Daniel)\
**Post date:** [October 26, 2016, 11:06am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/11 "2016-10-26T11:06:54Z")

</div>

Hi I found solution.

I delete all indecies in data directory in elasticsearch and restart elasticsearch, logstash  
I can see geo\_point and could able to use map!

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/7db634b5e4fd8dfb36f0b245946ca4e1d31a10fc.png)  
Thanks.!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:32am UTC](https://discuss.elastic.co/t/could-not-able-to-use-geo-ip-in-logstash-2-4/63689/12 "2017-07-06T04:32:39Z")

</div>


