# Could not locate that index-pattern-field (id: source.geo.location)

**URL:** <https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860>\
**Category:** Kibana\
**Created:** [April 22, 2019, 1:58pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860 "2019-04-22T13:58:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![remimikalsen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/remimikalsen/32/44486_2.png) [@remimikalsen](https://discuss.elastic.co/u/remimikalsen)\
**Post date:** [April 22, 2019, 1:58pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860/1 "2019-04-22T13:58:55Z")

</div>

I'm using Filebeat+Kibana+Elasticsearch 7.0.0.  
I have one filebeat agent and one elasticsearch node.  
I've activated the nginx module in filebeat and successfully added a geoip pipeline in Elasticsearch. When I open a random Nginx access log entry, I get populated values in fields such as:

```
source.geo.location.lat
source.geo.location.lon
source.geo.city_name
etc.

```

However, when I try to visualize default Kibana dashboards like **[Filebeat Nginx] Overview ECS** i get stuck with messages like **Could not locate that index-pattern-field (id: source.geo.location)** and **Saved "field" parameter is now invalid. Please select a new field.**

I've tried running filebeat setup -e on the following filebeat.yaml:

```
filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: true

filebeat.modules:
- module: nginx

filebeat.autodiscover:
  providers:
    - type: docker
      hints.enabled: true
      default.disable: true

output.elasticsearch:
  hosts: 'elasticsearch:9200'
  pipeline: geoip-info

setup.template.overwrite: true

setup.kibana:
  host: "kibana:5601"

```

The geoip-info pipeline is PUT into elasticsearch via the Kibana console:

```
PUT _ingest/pipeline/geoip-info
{
  "description": "Add geoip info",
  "processors": [
    ...
    {
      "geoip": {
        "field": "source.ip",
        "target_field": "source.geo",
        "ignore_missing": true
      }
    },
    ...
  ]
}

```

The field source.geo.location exists in fields.yaml, and as stated earlier, log results are corretcly resolved geo-wise.

Please advice how I can have the maps show up correcly in Kibana with IPs plotted.

PS! If I ignore the added pipeline in the filebeat.yaml and rely on the geoip processor in the default nginx access ingest, it behaves the exact same way. Not working in Kibana.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [April 22, 2019, 8:34pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860/2 "2019-04-22T20:34:50Z")

</div>

@thomasneirynck - can you please shed more light here?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [April 22, 2019, 8:48pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860/3 "2019-04-22T20:48:26Z")

</div>

hi @remimikalsen

this might be more of a filebeat question which is not my area of expertise.

but can you verify two things:

- Does the mapping of your index have a field of type `geo_point` with name `source.geo.location`?
- check an example document in Discover. Does it correctly show a property at that field with `lat`and `lon` properties?

If that is the case, Kibana should be able to create a map (e.g. coordinate map or a map in the Maps-app).

---

<div class="post-metadata">

**Author:** ![remimikalsen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/remimikalsen/32/44486_2.png) [@remimikalsen](https://discuss.elastic.co/u/remimikalsen)\
**Post date:** [April 22, 2019, 9:52pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860/4 "2019-04-22T21:52:05Z")

</div>

Thank you for the follow-up @thomasneirynck!

So answering your two questions:

1. When I run "GET \_mapping" I fond the following definition of location under source.geo:

Thus, no geo\_point type, as expected, as my location geo field is split into two sub-fields, lat and lon, when I look at random nginx log entries.

1. This is a Json example of my source-info from Discover:

I assume this means I should re-define my location field to be of type geo\_point. How would I do that? I already tried this:

```
PUT filebeat-7.0.0
{
  "mappings": {
    "properties": {
      "location": {
        "type": "geo_point"
      }
    }
  }
}

```

This gave me a **"resource\_already\_exists\_exception"**.

Also what confuses me is that the "location" field is defined the following way in my /usr/share/filebeat/fields.yml file when running a container with the docker image **[docker.elastic.co/beats/filebeat:7.0.0](http://docker.elastic.co/beats/filebeat:7.0.0)**:

```
- name: geo.location
  level: core
  type: geo_point
  description: Longitude and latitude.
  example: '{ "lon": -73.614830, "lat": 45.505918 }'

```

I would really appreciate some more input here!

---

<div class="post-metadata">

**Author:** ![remimikalsen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/remimikalsen/32/44486_2.png) [@remimikalsen](https://discuss.elastic.co/u/remimikalsen)\
**Post date:** [April 23, 2019, 7:07am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860/5 "2019-04-23T07:07:08Z")

</div>

Hi, I just made this work. I don' know how or why, but somehow my indexing templates were off. For future reference, I fixed it by:

1. Stopping filebeat (and for others, anything that might be causing writes to the Elasticsearch index)
2. Deleting all templates and indexed in Elasticsearch.
3. Restarting Kibana for good measure, as Kibana seems to dislike that I delete all Elasticsearch data.
4. Still with my filebeat container shut down, I ran the following one off commands:

- docker-compose run filebeat setup --template
- docker-compose run filebeat setup -e

Then, after starting up filebeat, the maps and dashboards in Kibana worked as expected.

No further arguments were needed as my docker-compose.yml mounts a valid filebeat.yaml config which already contains my kibana and elasticsearch targets.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2019, 7:13am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field-id-source-geo-location/177860/6 "2019-05-21T07:13:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
