# Filebeat Azure module not compatible with Maps visualisation

**URL:** <https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 2, 2021, 5:02pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910 "2021-05-02T17:02:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [May 2, 2021, 5:02pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910/1 "2021-05-02T17:02:06Z")

</div>

- I am using Filebeat Azure module to fetch activity logs and sign-in logs.
- Logstash is running between Filebeat and Elasticsearch and pushing data to a custom index `cloud-audit-azure`. Using a custom index to store data purposefully as we want to use index pattern `cloud-audit*` having indexes such as `cloud-audit-aws`, `cloud-audit-azure`.
- I copied its ingest pipeline and using the same to parse data.
- after seeing `source.geo.location.lat` and `source.geo.location.lon` data type as`number` I tried changing it to `geo_point` from mapping but no luck
- when changed to `geo_point`, cloud-audit-azure was visible in Maps visualization but it was letting me select only one of `source.geo.location.lat` or `source.geo.location.lon`.

Here is the pipeline file if you would like to see :

> <https://gist.github.com/ankitdevnalkar/4cc274bc204f394beaec90ec968b3460>

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [May 3, 2021, 6:16am UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910/2 "2021-05-03T06:16:19Z")

</div>

Can anyone help ?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 3, 2021, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910/3 "2021-05-03T13:11:38Z")

</div>

> [@ankitdevnalkar](#):
>
> when changed to `geo_point` , cloud-audit-azure was visible in Maps visualization but it was letting me select only one of `source.geo.location.lat` or `source.geo.location.lon` .

`source.geo.location` should be geo\_point, not the lat or long. What does you index mapping look like? How did you create it?

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [May 3, 2021, 1:18pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910/4 "2021-05-03T13:18:28Z")

</div>

hey @legoguy1000 thanks for your reply. I did not create the mapping, I tried changing type from ingest pipeline.

Index mapping is in the following gist :

> <https://gist.github.com/ankitdevnalkar/04d89eb899c8661484728f85bd8c0695>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 3:19pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-not-compatible-with-maps-visualisation/271910/5 "2021-05-31T15:19:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
