# ES7.4 returns unsupported symbol in geohash

**URL:** <https://discuss.elastic.co/t/es7-4-returns-unsupported-symbol-in-geohash/206306>\
**Category:** Elasticsearch\
**Created:** [November 3, 2019, 11:02pm UTC](https://discuss.elastic.co/t/es7-4-returns-unsupported-symbol-in-geohash/206306 "2019-11-03T23:02:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [November 3, 2019, 11:02pm UTC](https://discuss.elastic.co/t/es7-4-returns-unsupported-symbol-in-geohash/206306/1 "2019-11-03T23:02:55Z")

</div>

Mapping defined as this:

```
  "source": {
    "properties": {
      "address": {
        "type": "keyword",
        "fields": {
          "text": { "type" : "text" }
        }
      },
      "ip": { "type": "ip" },
      "port": { "type": "long" },
      "bytes": { "type": "long" },
      "geo": {
        "properties": {
          "city_name": { "type": "keyword" },
          "country_name": { "type": "keyword" },
          "continent_code": { "type" : "keyword" },
          "location": { "type": "geo_point" }
        }
      },
      "as": {
        "properties": {
          "number": { "type": "long" },
          "organization": {
            "properties": {
              "name": { "type": "keyword" }
            }
          }
        }
      }
    }

```

Errors received when ingesting data:

```
[2019-11-03T23:26:36,449][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"esxi_network-2019.11.02", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x88ada96>], :response=>{"index"=>{"_index"=>"esxi_network-2019.11.02", "_type"=>"_doc", "_id"=>"2BNgM24BZDNolIqijqjw", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [source.geo.location] of type [geo_point]", "caused_by"=>{"type"=>"parse_exception", "reason"=>"unsupported symbol [.] in geohash [12.5341]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"unsupported symbol [.] in geohash [12.5341]"}}}}}}
[2019-11-03T23:26:36,449][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"esxi_network-2019.11.02", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0xeddc1fc>], :response=>{"index"=>{"_index"=>"esxi_network-2019.11.02", "_type"=>"_doc", "_id"=>"2RNgM24BZDNolIqijqjw", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [source.geo.location] of type [geo_point]", "caused_by"=>{"type"=>"parse_exception", "reason"=>"unsupported symbol [-] in geohash [-78.3715]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"unsupported symbol [-] in geohash [-78.3715]"}}}}}}

```

Sample of data entry:

```
 ...
"source" => {
    "geo" => {
         "city_name" => "SÃ£o Paulo",
      "country_name" => "Brazil",
    "continent_code" => "SA",
          "location" => [
        [0] "-46.6417",
        [1] "-23.5733"
    ]
},
     "as" => {
          "number" => "28666",
    "organization" => {
        "name" => "HOSTLOCATION LTDA"
    }
},
...

```

data is picked from geoip lookups like this:

```
 geoip {
   default_database_type => 'City'
   database => '/usr/share/GeoIP2/GeoLite2-City.mmdb'
   cache_size => 5000
   source => '[source][ip]'
   target => '[@metadata][geo]'
   fields => ['city_name','continent_code','country_name','latitude','longitude']
   add_field => [
     '[source][geo][city_name]', '%{[@metadata][geo][city_name]}',
     '[source][geo][country_name]', '%{[@metadata][geo][country_name]}',
     '[source][geo][continent_code]', '%{[@metadata][geo][continent_code]}',
     '[source][geo][location]', '%{[@metadata][geo][longitude]}',
     '[source][geo][location]', '%{[@metadata][geo][latitude]}'
   ]
   remove_field => ['[@metadata][geo]']
 }
 # sometimes city still is unknown on successful lookups
 if [source][geo][city_name] == '%{[@metadata][geo][city_name]}' {
   mutate { remove_field => ['[source][geo][city_name]'] }
 }

```

TIA for any hints as to what I might be doing wrong!

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [November 4, 2019, 8:10am UTC](https://discuss.elastic.co/t/es7-4-returns-unsupported-symbol-in-geohash/206306/2 "2019-11-04T08:10:44Z")

</div>

Seem if I do this then it ingests fine 😉

```
mutate { convert => { '[source][geo][location]' => 'float' } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2019, 8:10am UTC](https://discuss.elastic.co/t/es7-4-returns-unsupported-symbol-in-geohash/206306/3 "2019-12-02T08:10:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
