# Geo\_point automatically

**URL:** <https://discuss.elastic.co/t/geo-point-automatically/273183>\
**Category:** Logstash\
**Created:** [May 17, 2021, 2:05pm UTC](https://discuss.elastic.co/t/geo-point-automatically/273183 "2021-05-17T14:05:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Emi\_lie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emi_lie/32/88851_2.png) [@Emi\_lie](https://discuss.elastic.co/u/Emi_lie)\
**Post date:** [May 17, 2021, 2:05pm UTC](https://discuss.elastic.co/t/geo-point-automatically/273183/1 "2021-05-17T14:05:42Z")

</div>

Hello,

I struggle to add the geo\_point to my index, automatically.

All the solutions I found, official and unofficial, indicate that it is necessary to pass by the devTools to make a PUT of the index. But I use elasticSearch on a docker, and I would like geoip.coordinates to be of type "geo\_point" automatically.

We can't do ' convert =\> ["[geoip][coordinates]", "geo\_point"] ' because it is not supported.

Is there another way to convert?

logstash.conf file

```auto
    input {
        beats {
            port => 5000
            host => "0.0.0.0"
        }
    }
    filter {
        grok {
            match => ["message", "\[%{IP:server_ip}\]\[%{IP:client_ip}\] - %{NUMBER:size} %{NUMBER:duration} ms"]

        }
        geoip {
            source => "client_ip"
            target => "geoip"
            database => "/usr/share/logstash/config/GeoLite2City.mmdb"
            add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
            add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
        }
        mutate {
            convert => {
                "duration" => "float"
                "size" => "float"
            }
        }
        mutate {
            convert => ["[geoip][coordinates]", "float"]
        }
    }

    output {
        elasticsearch {
            hosts => ["172.10.0.2:3600"]
            index => "datelogs-%{+YYYY.MM.dd}"
            # template_name => "logs-*" # dont know if its necessary
        }
        stdout { codec => rubydebug }
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 17, 2021, 3:10pm UTC](https://discuss.elastic.co/t/geo-point-automatically/273183/2 "2021-05-17T15:10:44Z")

</div>

The concept of geo\_point does not exist in logstash. The only way to tell elasticsearch that a field is a geo\_point is to use a [template](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html).

---

<div class="post-metadata">

**Author:** ![Emi\_lie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emi_lie/32/88851_2.png) [@Emi\_lie](https://discuss.elastic.co/u/Emi_lie)\
**Post date:** [May 17, 2021, 3:39pm UTC](https://discuss.elastic.co/t/geo-point-automatically/273183/3 "2021-05-17T15:39:40Z")

</div>

Thanks for the answer!  
When I create the index, geoip.coordinates is already a number and I can't change it.  
I already have data.

How to change it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 17, 2021, 4:14pm UTC](https://discuss.elastic.co/t/geo-point-automatically/273183/4 "2021-05-17T16:14:24Z")

</div>

> [@Emi\_lie](#):
>
> How to change it?

You cannot change the type of a field once it has been indexed. You would need to create a new index (that has a template). One option for doing that is the [reindex](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) API.

---

<div class="post-metadata">

**Author:** ![Emi\_lie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emi_lie/32/88851_2.png) [@Emi\_lie](https://discuss.elastic.co/u/Emi_lie)\
**Post date:** [May 18, 2021, 8:40am UTC](https://discuss.elastic.co/t/geo-point-automatically/273183/5 "2021-05-18T08:40:00Z")

</div>

After much research, I discovered several points.

First of all here is my final version of logstash.conf

```auto
input {
    beats {
        port => 5000
        host => "0.0.0.0"
    }
}
filter {
    grok {
        match => ["message", "\[%{IP:server_ip}\]\[%{IP:client_ip}\] - %{NUMBER:size} %{NUMBER:duration} ms"]
    }
    geoip {
        source => "client_ip"
    }
    mutate {
        convert => {
            # even if it is a NUMBER above, the final type will be string, mutate allows to make a float
            "duration" => "float"
            "size" => "float"
        }
    }
}
output {
    elasticsearch {
        hosts => ["172.10.0.2:3600"]
        index => "logstash-%{+YYYY.MM.dd}" #important
    }
    stdout { codec => rubydebug }
}

```

Now the list of points :

- For info I use docker with elasticsearh, kibana, logstash, filebeat on it

- When the docker starts, it creates a logstash template. You can see it by going to the devTools of Kibana : GET /\_template/logstash  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/1/1147c226b9b8d4c73b3342c10d2afff0ad856f2f.png)  
in this template, we can see the geo\_point needed for our maps.  
So to link this template to our log files, our indexes must have the name of the template, here it is "logstash".  
To give this name, go to logstash.conf, output, elasticsearch, index.

- In Kibana, index patterns, the index name should be "logstash-\*" to encompass our log files which are now called "logstash-{DATE}"  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a754488aabf6e05345eab86186899dd8c3230bc.png)

- Be careful that docker containers do not keep old configurations (indexes, Kibana mappings for example)

- mutate on geoip is useless in logstash.conf, don't write it

```auto
mutate {
    convert => ["[geoip][location]", "float"] # useless!
}

```

I hope it helps someone.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2021, 8:40am UTC](https://discuss.elastic.co/t/geo-point-automatically/273183/6 "2021-06-15T08:40:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
