# Geo location issues

**URL:** <https://discuss.elastic.co/t/geo-location-issues/67200>\
**Category:** Kibana\
**Created:** [November 25, 2016, 2:42pm UTC](https://discuss.elastic.co/t/geo-location-issues/67200 "2016-11-25T14:42:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 25, 2016, 2:42pm UTC](https://discuss.elastic.co/t/geo-location-issues/67200/1 "2016-11-25T14:42:07Z")

</div>

Hi All,

Am using Elastic stack for analysing the syslogs and i have geo filter enabled in logstash configuration and when I visualize it kibana the values getting divided like this.  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/cc1b87a9f2794b58c7a8bee4705559dd3c025309.png)

We know the Los angeles is a city ,but my values are coming separately for los and angeles ,if its a place with single name I dont have issues but if a place second name (like San Francisco , Los angeles ) logs are getting divided and it shows some logs for first name and some logs for second name.

Please any one can help me,it would be great:)

Thanks ,  
Raj

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [November 25, 2016, 8:04pm UTC](https://discuss.elastic.co/t/geo-location-issues/67200/2 "2016-11-25T20:04:17Z")

</div>

Hi @Raj_Kumar,

the reason for the results you are seeing is that Elasticsearch analyzes string fields by default and therefore splits the field content into terms. To avoid that you have two possibilities, depending on the version of Elasticsearch that you are using.

If you are using version 5.0 or above, the unanalyzed contents of the string field `country` are stored in `country.keyword` automatically.

In previous versions you can enable a similar behavior by specifying `not_analyzed` as the `index` value of the field. See [https://www.elastic.co/guide/en/elasticsearch/reference/2.4/multi-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/multi-fields.html) for examples.

In both cases, the city names contained in the properly configured fields will be treated as keywords and not individual terms for queries and should appear as expected in Kibana.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 28, 2016, 12:05pm UTC](https://discuss.elastic.co/t/geo-location-issues/67200/3 "2016-11-28T12:05:48Z")

</div>

Thank you Felix for your reply ,let me try this 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2016, 12:05pm UTC](https://discuss.elastic.co/t/geo-location-issues/67200/4 "2016-12-26T12:05:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
