# Create a new field using two separate fields to produce geo-point

**URL:** <https://discuss.elastic.co/t/create-a-new-field-using-two-separate-fields-to-produce-geo-point/99785>\
**Category:** Elasticsearch\
**Created:** [September 8, 2017, 4:44am UTC](https://discuss.elastic.co/t/create-a-new-field-using-two-separate-fields-to-produce-geo-point/99785 "2017-09-08T04:44:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![layeghy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/layeghy/32/18902_2.png) [@layeghy](https://discuss.elastic.co/u/layeghy)\
**Post date:** [September 8, 2017, 4:44am UTC](https://discuss.elastic.co/t/create-a-new-field-using-two-separate-fields-to-produce-geo-point/99785/1 "2017-09-08T04:44:50Z")

</div>

I am using Elasticsearch and Kibana to visualize network traffic which includes Latitude and Longitude coordinates for IP addresses in a separate filed both of type "number"

As far as I could find in the documentations I needed to have a unique field for coordinates which should include both Latitude and Longitude and its type should be "geo-point".

I do not want Logstash to do this for me, as the package I use to create traffic flows directly writes to Elastic search.  
So I thought maybe a possible solution is to create a new scripted field of string type, concatenate them with a "," and change the mapping as "geo-point" something like this:

If Longitude= 100 and Latitude=50 then my new scripted field that I named "Geo\_Loc" would be:  
Geo\_Loc=100,50

 ![kibana](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da71afb497baf27b14d6dd3959f16543bb9c17ec.png)

This is exactly what I see when I explore my data in Discover tab in Kibana. I have also managed to create a new visualization using tile maps by applying Geohash aggregation on my scripted field "Geo\_Loc".

However, what I see is an empty world map like this

 ![kibana1](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77890610ea202ca4bcb39265b391eb0850a5de1d.png)

(Note when I change the map type in the option tab, from scaled circled markers to other types such as heat map or etc I cannot see any changes, I am connected to internet and can browse without any problem)  
I appreciate if someone can tell what's wrong and which step I am doing incorrectly.  
Siamak

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [September 8, 2017, 10:34am UTC](https://discuss.elastic.co/t/create-a-new-field-using-two-separate-fields-to-produce-geo-point/99785/2 "2017-09-08T10:34:44Z")

</div>

Query-time patching of omissions to your indexing logic will only get you so far.

You can't expect client-side javascript to make up for a lack of spatial indexing in your server.

> [@layeghy](#):
>
> I do not want Logstash to do this for me, as the package I use to create traffic flows directly writes to Elastic search.

Have a look at using [ingest pipelines](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) to massage your JSON immediately before insertion into elasticsearch.

---

<div class="post-metadata">

**Author:** ![layeghy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/layeghy/32/18902_2.png) [@layeghy](https://discuss.elastic.co/u/layeghy)\
**Post date:** [September 10, 2017, 11:17pm UTC](https://discuss.elastic.co/t/create-a-new-field-using-two-separate-fields-to-produce-geo-point/99785/3 "2017-09-10T23:17:44Z")

</div>

Thanks.  
I will have a look.

Cheers,  
Siamak

---

<div class="post-metadata">

**Author:** ![layeghy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/layeghy/32/18902_2.png) [@layeghy](https://discuss.elastic.co/u/layeghy)\
**Post date:** [September 14, 2017, 1:07am UTC](https://discuss.elastic.co/t/create-a-new-field-using-two-separate-fields-to-produce-geo-point/99785/4 "2017-09-14T01:07:20Z")

</div>

Hi Mark,

I created a pipeline like this:

```auto
PUT _ingest/pipeline/1
{
  "description" : "combines two fields",
  "processors" : [
    {
      "append" : {
        "field": "Geo2",
        "value": "doc['DST_IP_LAT'].value , doc['DST_IP_LONG'].value"
      }
    }
  ]
}

```

where the two fields, DST\_IP\_LAT and DST\_IP\_LONG include latitude and longitude respectively. I tried these as well

```auto
PUT _ingest/pipeline/1
{
  "description" : "combines two fields",
  "processors" : [
    {
      "append" : {
        "field": "Geo2",
        "value": "DST_IP_LAT , DST_IP_LONG"
      }
    }
  ]
}

```

and I applied the pipeline in the input. However, what I get in the output is exactly"

```auto
"doc['DST_IP_LAT'].value , doc['DST_IP_LONG'].value"

```

or

```auto
"DST_IP_LAT , DST_IP_LONG"

```

and not their values ☹

I am sorry for asking trivial question, but I could not find it anywhere in Elasticsearch documentation explained clearly (for a beginner like me).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2017, 1:07am UTC](https://discuss.elastic.co/t/create-a-new-field-using-two-separate-fields-to-produce-geo-point/99785/5 "2017-10-12T01:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
