# EFK missing geo\_point

**URL:** <https://discuss.elastic.co/t/efk-missing-geo-point/321445>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [December 17, 2022, 9:15am UTC](https://discuss.elastic.co/t/efk-missing-geo-point/321445 "2022-12-17T09:15:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![khteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khteh/32/147573_2.png) [@khteh](https://discuss.elastic.co/u/khteh)\
**Post date:** [December 17, 2022, 9:15am UTC](https://discuss.elastic.co/t/efk-missing-geo-point/321445/1 "2022-12-17T09:15:19Z")

</div>

I am running EFK using ECK 8.5.3. fluentd `ConfigMap`:

```auto
      @type geoip
      # Specify one or more geoip lookup field which has ip address (default: host)
      geoip_lookup_keys IP

      # Specify optional geoip database (using bundled GeoLiteCity databse by default)
      # geoip_database "/path/to/your/GeoIPCity.dat"
      # Specify optional geoip2 database
      # geoip2_database "/path/to/your/GeoLite2-City.mmdb" (using bundled GeoLite2-City.mmdb by default)
      # Specify backend library (geoip2_c, geoip, geoip2_compat)
      backend_library geoip2_c

      # Set adding field with placeholder (more than one settings are required.)
     <record>
        city ${city.names.en["IP"]}
        latitude ${location.latitude["IP"]}
        longitude ${location.longitude["IP"]}
        country_code ${country.iso_code["IP"]}
        country_name ${country.names.en["IP"]}
        postal_code ${postal.code["IP"]}
        location_properties '{ "lat" : ${location.latitude["IP"]}, "lon" : ${location.longitude["IP"]} }'
        location_string ${location.latitude["IP"]},${location.longitude["IP"]}
        location_array '[${location.longitude["IP"]},${location.latitude["IP"]}]'
      </record>      

```

ES template:

```auto
      "mappings": {
          "properties": {
              "location_properties": { "type": "geo_point" },
              "location_string": { "type": "geo_point" },
              "location_array": { "type": "geo_point" }
          }
      }

```

I don't see any of the properties in Kibana ECK 8.5.3 at all. What do I miss?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 18, 2022, 10:37pm UTC](https://discuss.elastic.co/t/efk-missing-geo-point/321445/2 "2022-12-18T22:37:32Z")

</div>

What is the output that fluentd is providing?

Ultimately though. this might be more of a fluentd issue than an Elasticsearch one.

---

<div class="post-metadata">

**Author:** ![khteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khteh/32/147573_2.png) [@khteh](https://discuss.elastic.co/u/khteh)\
**Post date:** [December 19, 2022, 12:48am UTC](https://discuss.elastic.co/t/efk-missing-geo-point/321445/3 "2022-12-19T00:48:37Z")

</div>

Fixed. It need to be in JSON format string.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2023, 12:49am UTC](https://discuss.elastic.co/t/efk-missing-geo-point/321445/4 "2023-01-16T00:49:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
