# Error with basic geo\_point setup in logstash

**URL:** <https://discuss.elastic.co/t/error-with-basic-geo-point-setup-in-logstash/82175>\
**Category:** Logstash\
**Created:** [April 12, 2017, 2:04pm UTC](https://discuss.elastic.co/t/error-with-basic-geo-point-setup-in-logstash/82175 "2017-04-12T14:04:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [April 12, 2017, 2:04pm UTC](https://discuss.elastic.co/t/error-with-basic-geo-point-setup-in-logstash/82175/1 "2017-04-12T14:04:10Z")

</div>

I am trying use a basic geo\_point/geoip setup in logstash.

My template for ES has the following field:  
`"source_geoip" : { "type" : "geo_point" }`

Then, in my logstash config, I am trying the following:

> ```
> geoip {
> source => "source_ip"
> target => "source_geoip"
> add_tag => ["success_geoip"]
> tag_on_failure => ["geoip_error", "geoip_source_error"]
> }
> 
> ```

I'm getting an error in my logstash files stating:

> "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse", "caused\_by"=\>{"type"=\>"parse\_exception", "reason"=\>"field must be either [lat], [lon] or [geohash]"}}}}}

I can't figure out what is going on. I can see through the rubydebug that the IPs are properly getting parsed on the logstash side. It looks like the insert into ES isn't working properly.

Can anyone give me any clue into what I need to do?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 12, 2017, 2:21pm UTC](https://discuss.elastic.co/t/error-with-basic-geo-point-setup-in-logstash/82175/2 "2017-04-12T14:21:07Z")

</div>

You are sending all of the geoip data to a _nested object_ called `source_geoip`. Your mapping missed the fact that `location` is a sub-field of that `source_geoip` object.

Take some cues from the [default template that comes with Logstash](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/v7.2.2/lib/logstash/outputs/elasticsearch/elasticsearch-template-es5x.json#L34-L42):

```auto
        "geoip" : {
          "dynamic": true,
          "properties" : {
            "ip": { "type": "ip" },
            "location" : { "type" : "geo_point" },
            "latitude" : { "type" : "half_float" },
            "longitude" : { "type" : "half_float" }
          }
        }

```

Note how `geoip` is an object with nested fields? The `location` field is the one you want to be a `geo_point`.

Your mapping which has

```auto
"source_geoip" : { "type" : "geo_point" }

```

Should look more like:

```auto
        "source_geoip" : {
          "dynamic": true,
          "properties" : {
            "ip": { "type": "ip" },
            "location" : { "type" : "geo_point" },
            "latitude" : { "type" : "half_float" },
            "longitude" : { "type" : "half_float" }
          }
        }

```

---

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [April 12, 2017, 2:59pm UTC](https://discuss.elastic.co/t/error-with-basic-geo-point-setup-in-logstash/82175/3 "2017-04-12T14:59:26Z")

</div>

Thank you so much.

This should really be in some sort of official documentation, perhaps on the geoip filter page for logstash.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 12, 2017, 4:10pm UTC](https://discuss.elastic.co/t/error-with-basic-geo-point-setup-in-logstash/82175/4 "2017-04-12T16:10:24Z")

</div>

Happy to help. Mapping is a rather tricky concept, though—more than a single page of documentation can cover well.

We did create a blog post to help make custom mappings with Logstash, though: [https://www.elastic.co/blog/logstash\_lesson\_elasticsearch\_mapping](https://www.elastic.co/blog/logstash_lesson_elasticsearch_mapping)

If you had know about the blog post, and used the examples in the blog there as a template, you would have nailed this, I'm sure.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2017, 4:21pm UTC](https://discuss.elastic.co/t/error-with-basic-geo-point-setup-in-logstash/82175/5 "2017-05-10T16:21:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
