# Geo\_point for conection map

**URL:** <https://discuss.elastic.co/t/geo-point-for-conection-map/215363>\
**Category:** Logstash\
**Created:** [January 16, 2020, 5:15pm UTC](https://discuss.elastic.co/t/geo-point-for-conection-map/215363 "2020-01-16T17:15:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_Campos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_campos/32/11259_2.png) [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Post date:** [January 16, 2020, 5:15pm UTC](https://discuss.elastic.co/t/geo-point-for-conection-map/215363/1 "2020-01-16T17:15:59Z")

</div>

I am currently mapping the data of a snort, but I was trying to convert two fields, which are the IP source and destination to geo\_point. I am doing this in order to be able to create the map connection visualization.

Only location places me as geo\_point

![imagen](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73abee5546252c30de3ca0c49ab07bb71e9cd2b1.png)

But the field I need for connection maps is string

![imagen](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fdabad116efd5a4ed390d05596bd12436ef31874.png)

This is what I have tried to do.

```
  geoip {
      source => "source"
       target => "geoip_source"
        }

       geoip {
      source => "destination"
       target => "geoip_destination"
             }

```

Thanks for support.

Greetings

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2020, 6:19pm UTC](https://discuss.elastic.co/t/geo-point-for-conection-map/215363/2 "2020-01-16T18:19:37Z")

</div>

You will need a [template](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html) to tell elasticsearch that those fields a geo\_points. The [default](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json) template includes an example of how to make a field a geo\_point.

---

<div class="post-metadata">

**Author:** ![Jose\_Campos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_campos/32/11259_2.png) [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Post date:** [January 27, 2020, 3:42pm UTC](https://discuss.elastic.co/t/geo-point-for-conection-map/215363/3 "2020-01-27T15:42:46Z")

</div>

Thanks a lot Badger

I understand that this must be indicated to ES, but I have not yet found any concrete way on how to do it.

Excuse me, I'm first time in this.

Greetings

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2020, 3:43pm UTC](https://discuss.elastic.co/t/geo-point-for-conection-map/215363/4 "2020-02-24T15:43:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
