# Exactly - how to map geoip.location to geo\_point- WTF!

**URL:** <https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812>\
**Category:** Elasticsearch\
**Created:** [December 13, 2016, 4:03am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812 "2016-12-13T04:03:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bob\_Metelsky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bob_metelsky/32/11387_2.png) [@Bob\_Metelsky](https://discuss.elastic.co/u/Bob_Metelsky)\
**Post date:** [December 13, 2016, 4:03am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812/1 "2016-12-13T04:03:43Z")

</div>

Folks - I'm at a complete loss here. I've scoured the web trying to find out how to do this and this just seems unnecessarily complicated.

Can someone point me to a working example of what is needed to map my data to geo\_point

This is truly ridiculous - how such a useful feature can be so hidden and DIFFICULT to implement. How can this product grow at this rate of working documentation or ease of implementation

I'm definitely not a novice - but who ever manages this - needs to get with some working examples for the everyday man.

I've wasted a half day on this simple step

Let's see the elastic search support team...

my example  
[https://sites.google.com/site/developtroubleshooting/elastic-geoip/mapping2](https://sites.google.com/site/developtroubleshooting/elastic-geoip/mapping2)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 13, 2016, 4:27am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812/2 "2016-12-13T04:27:44Z")

</div>

`geoip.location` looks to be a number, not a geopoint.  
So it'd depend on what you have set your template/mapping to be.

---

<div class="post-metadata">

**Author:** ![Bob\_Metelsky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bob_metelsky/32/11387_2.png) [@Bob\_Metelsky](https://discuss.elastic.co/u/Bob_Metelsky)\
**Post date:** [December 13, 2016, 5:05am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812/3 "2016-12-13T05:05:26Z")

</div>

Mark I have a presentation to a users group re elastic. I'm trying to get an answer to using this feature. What exactly can you tell me based on my question? I don't know template mapping I'm using the main mapping file in the log stash Conf and posted on the website I linked.

---

<div class="post-metadata">

**Author:** ![Bob\_Metelsky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bob_metelsky/32/11387_2.png) [@Bob\_Metelsky](https://discuss.elastic.co/u/Bob_Metelsky)\
**Post date:** [December 13, 2016, 5:09am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812/4 "2016-12-13T05:09:16Z")

</div>

I'm using this template per log stash.conf

elasticsearch-apache-weblogs-geoip.json  
{  
"template" : "apache-weblogs-geoip\*",  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : true, "omit\_norms" : true},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true,  
"fielddata" : { "format" : "disabled" }  
}  
}  
}, {  
"string\_fields" : {  
"match" : "\*",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true,  
"fielddata" : { "format" : "disabled" },  
"fields" : {  
"raw" : {"type": "string", "index" : "not\_analyzed", "ignore\_above" : 256}  
}  
}  
}  
} ],  
"properties" : {  
"@timestamp": { "type": "date" },  
"@version": { "type": "string", "index": "not\_analyzed" },  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "float" },  
"longitude" : { "type" : "float" }  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Bob\_Metelsky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bob_metelsky/32/11387_2.png) [@Bob\_Metelsky](https://discuss.elastic.co/u/Bob_Metelsky)\
**Post date:** [December 13, 2016, 5:10am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812/5 "2016-12-13T05:10:53Z")

</div>

elasticsearch-apache-weblogs-geoip.json  
{  
"template" : "apache-weblogs-geoip\*",  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : true, "omit\_norms" : true},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true,  
"fielddata" : { "format" : "disabled" }  
}  
}  
}, {  
"string\_fields" : {  
"match" : "\*",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true,  
"fielddata" : { "format" : "disabled" },  
"fields" : {  
"raw" : {"type": "string", "index" : "not\_analyzed", "ignore\_above" : 256}  
}  
}  
}  
} ],  
"properties" : {  
"@timestamp": { "type": "date" },  
"@version": { "type": "string", "index": "not\_analyzed" },  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "float" },  
"longitude" : { "type" : "float" }  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 13, 2016, 5:20am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812/6 "2016-12-13T05:20:44Z")

</div>

Ok, and what does the applied mapping for the actual document look like? ie query the \_mapping endpoint and show us.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2017, 5:20am UTC](https://discuss.elastic.co/t/exactly-how-to-map-geoip-location-to-geo-point-wtf/68812/7 "2017-01-10T05:20:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
