# ELK-5.3.1 Kibana Tile map - No Compatable Fields: geo\_point

**URL:** <https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288>\
**Category:** Kibana\
**Created:** [April 22, 2017, 3:12pm UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288 "2017-04-22T15:12:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![lewis15](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lewis15/32/19088_2.png) [@lewis15](https://discuss.elastic.co/u/lewis15)\
**Post date:** [April 22, 2017, 3:12pm UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/1 "2017-04-22T15:12:41Z")

</div>

Running ELK Stack 5.3.1  
I am unable to create a Tile map because Kibana is defaulting to Field geo-point.  
I have not been able to fine anything in the logs that makes any sense to me about what is wrong.  
Sorry, no programing experience with Servers/PCs. Any help is appreciated

Picture1

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eef2a0da272b35cd04ab09e950decd93af2a4722.png)

Screen shot of missing geoip.location

 ![](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca20c57c137db6dae9f745e55b796d5d21ffac91.png)

This screen shot has a geoip.location

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/3/736ca1f21c5e969aca333c8cb17803a2f65e0b5e.png)

Event\_data.IpAddress & geoip.location are available

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e603f0b5a3cd54764ac6c346762dda5a8f5245a.png)

Empty geoip.location

 ![](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5edc46049bbf7b99c2c1a2dfdcdcdfef8f0d51c6.png)

Some event logs have an IP address in the log & some do not have an IP Address. This is normal for Windows Event Logs. Windows produces a huge number of event logs for a single logon. Some have some good information & some have blank fields

Geoip selections available

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8ae3fab36303d96c484b863c80bf97df0c89f889.png)

Logstash config file

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/f/afc429b252caf4e62de2e4e8b368752f9d58dc5a.png)

Thanks  
Lewis

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 24, 2017, 1:47am UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/2 "2017-04-24T01:47:11Z")

</div>

We just posted a blog about this topic that may help - [https://www.elastic.co/blog/geoip-in-the-elastic-stack](https://www.elastic.co/blog/geoip-in-the-elastic-stack)

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [April 24, 2017, 10:34pm UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/3 "2017-04-24T22:34:38Z")

</div>

You also might need to refresh the field mappings in the Index Pattern (open your `winlogbeat-*` index pattern and click the little refresh button

![](https://us1.discourse-cdn.com/elastic/original/3X/5/2/523d38ce9e2465850e300bb1c74d1f6c03df5cb8.jpg)

---

<div class="post-metadata">

**Author:** ![lewis15](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lewis15/32/19088_2.png) [@lewis15](https://discuss.elastic.co/u/lewis15)\
**Post date:** [May 2, 2017, 3:00pm UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/4 "2017-05-02T15:00:25Z")

</div>

I must be doing something incorrectly./wrong. After refreshing or  
rewriting the winlogbeat-\* index the fields remain the same 371 & no geoip  
field anywhere. Using the Console & the information in  
[https://www.elastic.co/guide/en/elasticsearch/plugins/5.3/using](https://www.elastic.co/guide/en/elasticsearch/plugins/5.3/using)  
-ingest-geoip.html I have almost the same results as indicated in the  
document. The differences are minor - the line locations of the  
information are not identical, but the information is the same. I do not  
have anything like geo-point.  
in any of my test systems that I am using to solve this problem.

Thanks for your help . I have learned a lot, but I am missing something.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [May 2, 2017, 8:33pm UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/5 "2017-05-02T20:33:53Z")

</div>

Are you refreshing/rewriting in elasticsearch? I was talking about in the Kibana Management app, choose "Index Patterns", then `winlogbeat-*` in the left column, and click the refresh button on the right hand side to refresh Kibana's cache of your fields

---

<div class="post-metadata">

**Author:** ![lewis15](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lewis15/32/19088_2.png) [@lewis15](https://discuss.elastic.co/u/lewis15)\
**Post date:** [May 2, 2017, 10:27pm UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/6 "2017-05-02T22:27:32Z")

</div>

Yes, that is what I did.

---

<div class="post-metadata">

**Author:** ![lewis15](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lewis15/32/19088_2.png) [@lewis15](https://discuss.elastic.co/u/lewis15)\
**Post date:** [May 2, 2017, 10:58pm UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/7 "2017-05-02T22:58:47Z")

</div>

Winlogstash1 is the management #1  
Winlogstash2 select Add New  
Winlogstash3 change from logstash-\* to winlogstbeat-\*  
Winlogstash4 selected refresh fields I also saved a new index by removing  
check in Index contains time based events..Had 371 fields, rechecked Index  
contains time based events & saved, again only 371 events.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7fcb98c27a7d1056c30adc1d8ff7323fe8833895.png)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/5/8/58a0ffd6896f0389ec1087e1a8c7820451e0688e.png)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73acd87fd7d82873b44cd90a4999082c3cfd6dca.png)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/6/e68bc8299d1a6ac7a4205ac7f6cc6d4972426ced.png)

---

<div class="post-metadata">

**Author:** ![lewis15](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lewis15/32/19088_2.png) [@lewis15](https://discuss.elastic.co/u/lewis15)\
**Post date:** [May 18, 2017, 11:51am UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/8 "2017-05-18T11:51:28Z")

</div>

Using [https://www.elastic.co/blog/geoip-in-the-elastic-stack](https://www.elastic.co/blog/geoip-in-the-elastic-stack), I am stuck at  
:

Next, we can save this pipeline to Elasticsearch  
[https://www.elastic.co/guide/en/elasticsearch/reference/5.3/put-pipeline-api.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.3/put-pipeline-api.html),  
set a template to make sure that the geoip valures are treated as a and  
then use Filebeat to push data directly to our cluster for ingestion and  
storage, with our added geoip info being added automatically!  
Am I suppose to make any changes to:

PUT \_ingest/pipeline/my-pipeline-id{  
"description" : "describe pipeline",  
"processors" : [  
{  
"set" : {  
"field": "foo",  
"value": "bar"  
}  
}  
]}

If so, I don't know what fields to change or what.

Also how do I set a template?

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2017, 11:51am UTC](https://discuss.elastic.co/t/elk-5-3-1-kibana-tile-map-no-compatable-fields-geo-point/83288/9 "2017-06-15T11:51:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
