# Geo\_point is not getting mapped correctly

**URL:** <https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156>\
**Category:** Logstash\
**Created:** [August 7, 2017, 9:24pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156 "2017-08-07T21:24:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [August 7, 2017, 9:24pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156/1 "2017-08-07T21:24:02Z")

</div>

Hello,

I am not sure if this is the proper place to ask this question.

I am parsing my log file with the following grok pattern taken from the logstash documentation as it is:

```
 input {
  beats {
    # The port to listen on for filebeat connections.
    port => 5044
    # The IP address to listen for filebeat connections.
    host => "0.0.0.0"
  }
}
filter {
   grok {
      match => { "message" => ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} %{DATA:[system][auth][ssh][method]} for (invalid user )?%{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]} port %{NUMBER:[system][auth][ssh][port]} ssh2(: %{GREEDYDATA:[system][auth][ssh][signature]})?",
           "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} user %{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]}",
           "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: Did not receive identification string from %{IPORHOST:[system][auth][ssh][dropped_ip]}",
           "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:\[%{POSINT:[system][auth][pid]}\])?: \s*%{DATA:[system][auth][user]} :( %{DATA:[system][auth][sudo][error]} ;)? TTY=%{DATA:[system][auth][sudo][tty]} ; PWD=%{DATA:[system][auth][sudo][pwd]} ; USER=%{DATA:[system][auth][sudo][user]} ; COMMAND=%{GREEDYDATA:[system][auth][sudo][command]}",
           "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:\[%{POSINT:[system][auth][pid]}\])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}",
           "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:\[%{POSINT:[system][auth][pid]}\])?: new user: name=%{DATA:[system][auth][user][add][name]}, UID=%{NUMBER:[system][auth][user][add][uid]}, GID=%{NUMBER:[system][auth][user][add][gid]}, home=%{DATA:[system][auth][user][add][home]}, shell=%{DATA:[system][auth][user][add][shell]}$",
           "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:\[%{POSINT:[system][auth][pid]}\])?: %{GREEDYMULTILINE:[system][auth][message]}"] }
      pattern_definitions => {
    "GREEDYMULTILINE"=> "(.|\n)*"
  }
      remove_field => "message"
   }
   date {
      match => ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
   }
   geoip {
      source => "[system][auth][ssh][ip]"
      target => "[system][auth][ssh][geoip]"
   }
}
output {
  elasticsearch {
    hosts => ["172.16.99.5:9200", "172.16.99.6"]
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

The problem is that the geoip does not make geo\_point so that it can be used with kibana maps. Any help in here?

---

<div class="post-metadata">

**Author:** ![elaair](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@elaair](https://discuss.elastic.co/u/elaair)\
**Post date:** [August 7, 2017, 10:02pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156/2 "2017-08-07T22:02:54Z")

</div>

Have you checked the mapping of the index? Please post it here.

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [August 7, 2017, 10:11pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156/3 "2017-08-07T22:11:07Z")

</div>

How can I do that?

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [August 7, 2017, 10:50pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156/4 "2017-08-07T22:50:51Z")

</div>

I hope this is what you need:

Couldn't paste it in here cause it's too large but you can find the index mapping at this link: [https://pastebin.com/3jCGV0kx](https://pastebin.com/3jCGV0kx)

---

<div class="post-metadata">

**Author:** ![elaair](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@elaair](https://discuss.elastic.co/u/elaair)\
**Post date:** [August 7, 2017, 11:24pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156/5 "2017-08-07T23:24:50Z")

</div>

I did not see the geopoint in the mapping. I have been struggling with this same issue. on two different occasions.  
1:[Geoip.location](https://discuss.elastic.co/t/geoip-location/95632)

2: [Converting a number for use in geo-point](https://discuss.elastic.co/t/converting-a-number-for-use-in-geo-point/95252)

I am very new to Elastic ( 3 weeks in ) myslef.

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [August 7, 2017, 11:39pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156/6 "2017-08-07T23:39:56Z")

</div>

I used to create template on elasticsearch 2.x to fix the geo\_point issue. It was working out of the box on 5.x until now. But this happened again. I have no idea how to fix it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2017, 11:40pm UTC](https://discuss.elastic.co/t/geo-point-is-not-getting-mapped-correctly/96156/7 "2017-09-04T23:40:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
