# Facing Issue in converting geoip.location to geo\_point datatype

**URL:** <https://discuss.elastic.co/t/facing-issue-in-converting-geoip-location-to-geo-point-datatype/160404>\
**Category:** Elasticsearch\
**Created:** [December 11, 2018, 3:33pm UTC](https://discuss.elastic.co/t/facing-issue-in-converting-geoip-location-to-geo-point-datatype/160404 "2018-12-11T15:33:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakesh\_Thangapandian](https://avatars.discourse-cdn.com/v4/letter/r/c0e974/32.png) [@Rakesh\_Thangapandian](https://discuss.elastic.co/u/Rakesh_Thangapandian)\
**Post date:** [December 11, 2018, 3:33pm UTC](https://discuss.elastic.co/t/facing-issue-in-converting-geoip-location-to-geo-point-datatype/160404/1 "2018-12-11T15:33:04Z")

</div>

Hi Community Members,

I have tried to generate the visualization using coordinate maps in kibana from nginx server logs which is streamed in elasticsearch storage, since i failed in type casting geo\_point datatype properly for geoip.location field i was not able to generate reports.

After researching on web, I have configured my logstach filter plugin like below, but it haven't worked out properly

LoGSTACH CONFIG FILE:

```
input {
  beats {
    port => 5044
  }

}

filter {

if [fileset][name] == "access" {
grok {
match => ["message" , "%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra_fields}"]
overwrite => ["message"]
}

  
geoip {
source => "clientip"
target => "geoip"
add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
add_tag => ["nginx-geoip"]
}

mutate {
    convert => ["response", "integer"]
    convert => ["bytes", "integer"]
    convert => ["responsetime", "float"]
    convert => ["[geoip][coordinates]", "float"]
    }

date {
match => ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]
remove_field => ["timestamp"]
}

useragent {
      source => "user_agent"    
}
}

else if [fileset][name] == "error" {
grok {
match => ["message" , "(?<timestamp>%{YEAR}[./-]%{MONTHNUM}[./-]%{MONTHDAY}[-]%{TIME}) \[%{LOGLEVEL:severity}\] %{POSINT:pid}#%{NUMBER}: %{GREEDYDATA:errormessage}(?:, client: (?<client>%{IP}|%{HOSTNAME}))(?:, server: %{IPORHOST:server})(?:, request: %{QS:request})?(?:, upstream: \"%{URI:upstream}\")?(?:, host: %{QS:host})?(?:, referrer: \"%{URI:referrer}\")"]
overwrite => ["message"]
}
 

geoip {
source => "client"
target => "geoip"
add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
add_tag => ["nginx-geoip"]
}
 
mutate {
    convert => ["[geoip][coordinates]", "float"]
   }

date {
match => ["timestamp" , "YYYY/MM/dd HH:mm:ss"]
remove_field => ["timestamp"]
}
}

output {
if [fileset][name] == "access" {
elasticsearch {
		hosts => "elasticsearch:9200"          
		index => "nginx-access"       
	}
}
else if [fileset][name] == "error" {
elasticsearch {
		hosts => "elasticsearch:9200"          
		index => "nginx-error"       
	}
}
}

```

Any Help will be greatly appreciated...

Thank You!

---

<div class="post-metadata">

**Author:** ![chandra0651](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra0651/32/30484_2.png) [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Post date:** [December 11, 2018, 6:18pm UTC](https://discuss.elastic.co/t/facing-issue-in-converting-geoip-location-to-geo-point-datatype/160404/2 "2018-12-11T18:18:44Z")

</div>

```
mutate {
                add_field => {
                "MLGeo" => "%{[geoip][latitude]}, %{[geoip][longitude]}"
                    }
                     }

```

I dont think you have to convert the type to float

---

<div class="post-metadata">

**Author:** ![Rakesh\_Thangapandian](https://avatars.discourse-cdn.com/v4/letter/r/c0e974/32.png) [@Rakesh\_Thangapandian](https://discuss.elastic.co/u/Rakesh_Thangapandian)\
**Post date:** [December 12, 2018, 2:42pm UTC](https://discuss.elastic.co/t/facing-issue-in-converting-geoip-location-to-geo-point-datatype/160404/3 "2018-12-12T14:42:28Z")

</div>

Tried the above mentioned changes, still I am getting "No Compatible Fields" in kibana coordinate map visualization, Which wants geo\_point type as field

---

<div class="post-metadata">

**Author:** ![chandra0651](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra0651/32/30484_2.png) [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Post date:** [December 12, 2018, 4:13pm UTC](https://discuss.elastic.co/t/facing-issue-in-converting-geoip-location-to-geo-point-datatype/160404/4 "2018-12-12T16:13:51Z")

</div>

You need to define mappings for geo point field before the index creation some thing like below

```
"MLGeo": {
            "type": "geo_point",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2019, 4:13pm UTC](https://discuss.elastic.co/t/facing-issue-in-converting-geoip-location-to-geo-point-datatype/160404/5 "2019-01-09T16:13:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
