# Error in parse Geo\_point in logstash

**URL:** <https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122>\
**Category:** Logstash\
**Created:** [December 17, 2017, 3:45pm UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122 "2017-12-17T15:45:41Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![yaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser/32/109240_2.png) [@yaser](https://discuss.elastic.co/u/yaser)\
**Post date:** [December 17, 2017, 3:45pm UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/1 "2017-12-17T15:45:41Z")

</div>

i send this json to logstash :

> { "location" :45.5 }

**this is my conf.d/config file ::**

> input {  
> rabbitmq {  
> user =\> 'user'  
> password =\> '**'  
> exchange =\> '**'  
> queue =\> '\*\*\*\*'  
> durable =\> true  
> host =\> 'ip'  
> subscription\_retry\_interval\_seconds =\> 5  
> codec =\> 'json'  
> type =\>'test\_type'  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["192.168.1.6:9200","192.168.1.7:9200"]  
> codec =\> 'json'  
> index =\> "index\_test"  
> }  
> }

**this is the error log of logstash ::**

> [logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>  
> ["index", {:\_id=\>nil, :\_index=\>"index\_test", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x4da5b444], :response=\>{"index"=\>{"\_index"=\>"index\_test", "\_type"=\>"doc", "\_id"=\>"ZMQfZWABq4vMDUHKdlPb", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse", "caused\_by"=\>{"type"=\>"parse\_exception", "reason"=\>"geo\_point expected"}}}}}

**and this is my mapping ::**

> PUT index\_test  
> {  
> "mappings": {  
> "test\_type": {  
> "properties": {  
> "location": {  
> "type": "geo\_point"  
> }  
> }  
> }  
> }  
> }

can anyone help ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 17, 2017, 9:56pm UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/2 "2017-12-17T21:56:24Z")

</div>

A location is a latitude and a longitude, you only have one of those.

---

<div class="post-metadata">

**Author:** ![yaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser/32/109240_2.png) [@yaser](https://discuss.elastic.co/u/yaser)\
**Post date:** [December 18, 2017, 5:04am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/3 "2017-12-18T05:04:17Z")

</div>

what you mean? if you speak about json data that i send , i check it in multiple models like ::

```
    \"location\" : {
        \"latitude\" : 41,
        \"longitude\" : 71

```

or ::

```
    \"location\" : {41, 71}

```

**i don't know what format work??**

can you please explain completely ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 18, 2017, 5:04am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/4 "2017-12-18T05:04:49Z")

</div>

> [@yaser](#):
>
> i send this json to logstash :
> 
> { "location" :45.5 }

That is not a proper geopoint, it is only one value.

---

<div class="post-metadata">

**Author:** ![yaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser/32/109240_2.png) [@yaser](https://discuss.elastic.co/u/yaser)\
**Post date:** [December 18, 2017, 5:46am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/5 "2017-12-18T05:46:46Z")

</div>

yes ofcourse , but i sent in in this mode :: "location" : {45,51} but logstash return this error in log :

`

**[2017-12-18T08:56:02,247][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch.**  
{:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"index\_test", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x1546c159], :response=\>{"index"=\>{"\_index"=\>"index\_test", "\_type"=\>"doc", "\_id"=\>"4cQWaGABq4vMDUHKBmb8", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse", "caused\_by"=\>{"type"=\>" **illegal\_argument\_exception**", "reason"=\>"illegal **latitude value [269.9999986588955] for location**"}}}}}

`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 18, 2017, 6:31am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/6 "2017-12-18T06:31:50Z")

</div>

> yes ofcourse , but i sent in in this mode :: "location" : {45,51} but logstash return this error in log :

`{45,51}` isn't valid JSON so I'm not sure what you mean.

---

<div class="post-metadata">

**Author:** ![yaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser/32/109240_2.png) [@yaser](https://discuss.elastic.co/u/yaser)\
**Post date:** [December 18, 2017, 9:31am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/7 "2017-12-18T09:31:35Z")

</div>

i mean , all other setting is ok ,? and my json format is the main problem ?? because i test many json format and they aren't work!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 18, 2017, 9:37am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/8 "2017-12-18T09:37:19Z")

</div>

Please show an example document.

---

<div class="post-metadata">

**Author:** ![yaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser/32/109240_2.png) [@yaser](https://discuss.elastic.co/u/yaser)\
**Post date:** [December 18, 2017, 9:44am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/9 "2017-12-18T09:44:57Z")

</div>

" **{"Data" : "{data}","Snr" : {snr},"SequenceNumber" : {seqNumber},"DeviceID" : "{device}","StationID" : "{station}","RSSI" : {rssi},"Latitude" : {lat},"Longitude" :{lng},"AvgSnr" : {avgSnr},"Duplicate" : "{duplicate}"}**",

**this send to rabbitmq as my json content**

**tnx , here it is: i want to send "Latitude" and "Longitude" to save geo\_point field but i can't.**  
and another thing that must know , all {rssi} , {snr} , {lat} , {lng} and .... , replace with real values.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 18, 2017, 10:53am UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/10 "2017-12-18T10:53:02Z")

</div>

Please show us what you actually send to Elasticsearch. You can temporarily replace your elasticsearch output with a `stdout { codec => rubydebug }` output to dump that raw events to the log.

---

<div class="post-metadata">

**Author:** ![yaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser/32/109240_2.png) [@yaser](https://discuss.elastic.co/u/yaser)\
**Post date:** [December 18, 2017, 7:48pm UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/11 "2017-12-18T19:48:02Z")

</div>

hi again and thank so much about your answers ,  
this is rubydebug ::

```
{
          "type" => "my_type",
      "@version" => "1",
    "@timestamp" => 2017-12-18T19:29:56.056Z,
      "location" => "1,5"
}

```

and still logstash log this ::

[2017-12-18T23:04:12,503][WARN][logstash.outputs.elasticsearch] **Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"my\_index", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x1549ea87], :response=\>{"index"=\>{"\_index"=\>"my\_index", "\_type"=\>"doc", "\_id"=\>"nmMea2ABSZoa10DTjIn5", "status"=\>400, "error"=\>**{"type"=\>"illegal\_argument\_exception", "reason"=\>"Rejecting mapping update to [my\_index] as the final mapping would have more than 1 type: [doc, my\_type]"}}}}

---

<div class="post-metadata">

**Author:** ![yaser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser/32/109240_2.png) [@yaser](https://discuss.elastic.co/u/yaser)\
**Post date:** [December 18, 2017, 9:32pm UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/12 "2017-12-18T21:32:12Z")

</div>

**solved ::**

by this configuration ::

i add **document\_type =\> "type1"** and it worked 😊

```
input {
  rabbitmq {
    user => "user"
    password => "pass"
    exchange => "exc"
    queue => "logstash"
    durable => true
    host => "ip"
    subscription_retry_interval_seconds => 5
    codec => "json"
  }
}
output {
  elasticsearch {
    hosts => ["192.168.1.6:9200","192.168.1.7:9200"]
    codec => "json"
    index => "my_index1"
    document_type => "type1"
   }
file {
              path => "/Log/rabbitmq_debug_events-%{+YYYY-MM-dd}"
             codec => rubydebug
             }
}

```

thank you elasticsearch team

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2018, 9:35pm UTC](https://discuss.elastic.co/t/error-in-parse-geo-point-in-logstash/112122/13 "2018-01-15T21:35:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
