# Error when trying to add documents layer to maps

**URL:** <https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500>\
**Category:** Kibana\
**Tags:** maps\
**Created:** [August 18, 2020, 10:32pm UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500 "2020-08-18T22:32:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![looknleap](https://avatars.discourse-cdn.com/v4/letter/l/ecccb3/32.png) [@looknleap](https://discuss.elastic.co/u/looknleap)\
**Post date:** [August 18, 2020, 10:32pm UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500/1 "2020-08-18T22:32:35Z")

</div>

I am trying to get a map visualization working, but I get the error: "Couldn't find any index patterns with geospatial fields"

As shown below, I have have the index template setup with a geoip field mapping (2 actually, client\_GeoIP and geoip), the logstash output to elasticsearch is set to create geoip fields, and I see what I believe to be correctly created geoip fields in a document.

I don't know what else needs to happen to be able to get this into maps.

Pipeline: WAF --\> Logstash --\> Elasticsearch

Versions:

- Elasticsearch: 7.9.0
- Logstash 7.9.0

**Here are the relevant fields from a syslog entry in Elasticsearch**

```
"Client_GeoIP": {
  "country_code2": "US",
  "ip": "161.0.10.82",
  "region_code": "NY",
  "longitude": -74.0014,
  "latitude": 40.7503,
  "location": {
    "lon": -74.0014,
    "lat": 40.7503
  },
},
"geoip": {
  "country_code2": "US",
  "ip": "161.0.10.82",
  "longitude": -74.0014,
  "latitude": 40.7503,
  "location": {
    "lon": -74.0014,
    "lat": 40.7503
  },
},

```

**Index Template (Relevant Portion)**

```auto
...
      "geoip": {
        "dynamic": true,
        "properties": {
          "ip": {
            "type": "ip"
          },
          "latitude": {
            "type": "half_float"
          },
          "location": {
            "type": "geo_point"
          },
          "longitude": {
            "type": "half_float"
          }
        }
      },
      "Client_GeoIP": {
        "dynamic": true,
        "type": "object",
        "properties": {
          "ip": {
            "type": "ip"
          },
          "latitude": {
            "type": "half_float"
          },
          "location": {
            "type": "geo_point"
          },
          "longitude": {
            "type": "half_float"
          }
        }
...

```

**Logstash syslog pipeline config (relevant portions)**

```auto
...
filter {
...
    if ([Client_IP]) {
        geoip { 
            source => "Client_IP"
            target => "Client_GeoIP"
        }
        geoip {
            source => "Client_IP"
        }
    }
}
output {
    elasticsearch {
...
    template_name => "syslog"
    }
}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 19, 2020, 12:11am UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500/2 "2020-08-19T00:11:57Z")

</div>

Seems correct. If you made changes after the initial index pattern was created you might need to go refresh it.

---

<div class="post-metadata">

**Author:** ![looknleap](https://avatars.discourse-cdn.com/v4/letter/l/ecccb3/32.png) [@looknleap](https://discuss.elastic.co/u/looknleap)\
**Post date:** [August 19, 2020, 3:27am UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500/3 "2020-08-19T03:27:37Z")

</div>

Well shoot, I wish you had not said that. I refreshed the index pattern right now just in case, but it did not change anything.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [August 19, 2020, 10:11am UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500/4 "2020-08-19T10:11:30Z")

</div>

Have you checked the conditions listed from the [Troubleshoot documentation page](https://www.elastic.co/guide/en/kibana/current/maps-troubleshooting.html#_index_not_listed_when_adding_layer). Looks you already did the second, though.

---

<div class="post-metadata">

**Author:** ![looknleap](https://avatars.discourse-cdn.com/v4/letter/l/ecccb3/32.png) [@looknleap](https://discuss.elastic.co/u/looknleap)\
**Post date:** [August 19, 2020, 2:53pm UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500/5 "2020-08-19T14:53:49Z")

</div>

Thanks for that. I had not seen that page.  
Good(ish) news! It turned out that one of the indices that I reindexed did not get the original index deleted. That fixed the issue with the original Client\_GeoIP field. Now I can select the syslog-\* index pattern in maps. However, I am now seeing that there are no options in the "select geo field" dropdown.

Edit: I just had to refresh the index pattern and then it worked. Thank you.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [August 19, 2020, 3:29pm UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500/6 "2020-08-19T15:29:30Z")

</div>

Glad it worked, cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2020, 3:29pm UTC](https://discuss.elastic.co/t/error-when-trying-to-add-documents-layer-to-maps/245500/7 "2020-09-16T15:29:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
