# Geo\_Point field is not coming

**URL:** <https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640>\
**Category:** Logstash\
**Created:** [September 15, 2017, 5:51am UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640 "2017-09-15T05:51:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shubham\_Mahajan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_mahajan/32/22140_2.png) [@Shubham\_Mahajan](https://discuss.elastic.co/u/Shubham_Mahajan)\
**Post date:** [September 15, 2017, 5:51am UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640/1 "2017-09-15T05:51:40Z")

</div>

Hi There, I am trying to parse apache logs using grok. but i am not seeing any geo-point type in my index. Please help.

**My template:**

```
{
  "template": "apache_filebeat",
    "settings": {
      "number_of_shards": 1,
      "number_of_replicas" : 0,
      "index.refresh_interval": "5s"
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
        {
          "strings": {
            "match": "*",
            "match_mapping_type": "string",
            "mapping": {
              "type": "string",
              "index": "not_analyzed"
            }
          }
        }
        ],
        "properties": {
			"geoip": {
				"properties": {
					"city_name":{"type":"string", "index":"not_analyzed"},
					"continent_code":{"type":"string"},
					"country_code2":{"type":"string"},
					"country_code3":{"type":"string"},
					"country_name":{"type":"string", "index":"not_analyzed"},
					"location": {"type": "geo_point"},
					"latitude": {"type": "half_float"},
					"longitude": {"type": "half_float"}
				}
			}
		  "@version": {
			"index": "not_analyzed",
			"type": "string"
		  }
        },
        "_all": {
          "enabled": false
        }
      }
    }
}

```

**and my config file:**

```
input {
  beats {
	port => 5044
  }
}

filter {
  grok {
    match => {
      "message" => '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} \[%{HTTPDATE:timestamp}\] "%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agent}'
    }
  }

  date {
    match => ["timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]
    locale => en
  }

  geoip {
    source => "clientip"
  }

  useragent {
    source => "agent"
    target => "useragent"
  }
}

output {
  stdout { }
  elasticsearch {
    hosts => "http://localhost:9200"
    index => "apache_filebeat"
    template => "./filebeat_apache_template.json"
    template_name => "filebeat_apache_template"
    template_overwrite => true
  }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 18, 2017, 7:58pm UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640/2 "2017-09-18T19:58:26Z")

</div>

What do the mappings of an actual index look like? What does an example event from that index look like?

---

<div class="post-metadata">

**Author:** ![Shubham\_Mahajan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_mahajan/32/22140_2.png) [@Shubham\_Mahajan](https://discuss.elastic.co/u/Shubham_Mahajan)\
**Post date:** [September 19, 2017, 7:36am UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640/3 "2017-09-19T07:36:18Z")

</div>

hey Magnus, i was able to parse the field as geo\_point, so was able to plot a map.

But i have another ques: As seen in above logstash config, clientip would be transformed using grok, but in the template do i need to define the ip field as type 'IP' everytime I want to plot the geo Map???

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2017, 11:51am UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640/4 "2017-09-19T11:51:40Z")

</div>

> As seen in above logstash config, clientip would be transformed using grok, but in the template do i need to define the ip field as type 'IP' everytime I want to plot the geo Map???

For a map to work you need a geo\_point field. Kibana doesn't care about the IP address.

---

<div class="post-metadata">

**Author:** ![Shubham\_Mahajan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_mahajan/32/22140_2.png) [@Shubham\_Mahajan](https://discuss.elastic.co/u/Shubham_Mahajan)\
**Post date:** [September 19, 2017, 12:05pm UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640/5 "2017-09-19T12:05:42Z")

</div>

But only when i passed this template, would it work. here i am defining both IP and location as specific types.

```
{
  "template": "apache_filebeat",
    "settings": {
      "number_of_shards": 1,
      "number_of_replicas" : 0,
      "index.refresh_interval": "5s"
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
        {
          "strings": {
            "match": "*",
            "match_mapping_type": "string",
            "mapping": {
              "type": "string",
              "index": "not_analyzed"
            }
          }
        }
        ],
        "properties": {
			"geoip": {
				"properties": {
					"city_name":{"type":"string", "index":"not_analyzed"},
					"continent_code":{"type":"string"},
					"ip": {"type":"ip"},
					"country_code2":{"type":"string"},
					"country_code3":{"type":"string"},
					"country_name":{"type":"string", "index":"not_analyzed"},
					"latitude": {"type": "half_float"},
					"longitude": {"type": "half_float"},
					"location": {"type": "geo_point"}
				}
			},
		  "@version": {
			"index": "not_analyzed",
			"type": "string"
		  }
        },
        "_all": {
          "enabled": true
        }
      }
    }
}

```

but before that i only defined location field and not the IP field. At that time it wasn't picking the location field.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2017, 2:18pm UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640/6 "2017-09-19T14:18:10Z")

</div>

Well, whatever caused the behavior you saw it wasn't the mapping of the IP address field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2017, 2:18pm UTC](https://discuss.elastic.co/t/geo-point-field-is-not-coming/100640/7 "2017-10-17T14:18:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
