# Geo point mapping

**URL:** <https://discuss.elastic.co/t/geo-point-mapping/125105>\
**Category:** Logstash\
**Created:** [March 22, 2018, 4:29am UTC](https://discuss.elastic.co/t/geo-point-mapping/125105 "2018-03-22T04:29:22Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pororo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pororo/32/27711_2.png) [@Pororo](https://discuss.elastic.co/u/Pororo)\
**Post date:** [March 22, 2018, 4:29am UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/1 "2018-03-22T04:29:22Z")

</div>

Hi,

my dataset basically consists of the geo-information, but the format is not as perfect as I can directly ingest them in and let ES recognize it as the geo point type.

```
{"geo_information": "united states/michigan/holt:[42.638,-84.522]"}

```

This is the original format. I am wondering if there is any preprocessing way in logstash to exact the lat and lon information from the original value. And make it turn into the geo point type.

P.S What I want is to keep the original data information and add more fields based on the original data information.

Something like:

```
{"geo_information": "united states/michigan/holt:[42.638,-84.522]"}
{“geo_lon” : 42.638}
{"geo_lat" : ...}

```

I did go through the document of geo-point, but kinda confused how to actually operate it in my specific case.

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 22, 2018, 5:23am UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/2 "2018-03-22T05:23:28Z")

</div>

You need to use grok or dissect to pull it apart and then assign it as lat + lon fields. There's nothing natively in Logstash to do this with your format.

---

<div class="post-metadata">

**Author:** ![Pororo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pororo/32/27711_2.png) [@Pororo](https://discuss.elastic.co/u/Pororo)\
**Post date:** [March 22, 2018, 8:49pm UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/3 "2018-03-22T20:49:49Z")

</div>

Thanks.

And also if I get two more fields like  
{“geo\_lon” : 42.638}  
{"geo\_lat" : ...}

How does ES recognize the type of those fields is the regular float or geo point. My goal is to make it be geo point.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 22, 2018, 8:56pm UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/4 "2018-03-22T20:56:39Z")

</div>

They need to be one of the structures as defined here - [https://www.elastic.co/guide/en/elasticsearch/reference/6.2/geo-point.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/geo-point.html) - and then the resultant field needs to be mapped accordingly.

---

<div class="post-metadata">

**Author:** ![Pororo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pororo/32/27711_2.png) [@Pororo](https://discuss.elastic.co/u/Pororo)\
**Post date:** [March 23, 2018, 4:31pm UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/5 "2018-03-23T16:31:37Z")

</div>

This is my updated config,

```
	grok{
		match => {[geo_information] => "%{GREEDYDATA}%{NUMBER:lat:float}%{GREEDYDATA}%{NUMBER:lon:float}%{GREEDYDATA}"}
		add_filed => {"location" => "[[lat],[lon]]"}
	}

```

When I actually ran it, it threw me

Grok regexp threw exception {:exception=\>"no implicit conversion of Array into String", :backtrace=\>["/Users/apple/Desktop/logstash-6.2.2/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:320:in `match'", "/Users/apple/Desktop/logstash-6.2.2/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:296:in`block in filter'", "org/jruby/RubyHash.java:1343:in `each'", "/Users/apple/Desktop/logstash-6.2.2/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:295:in`filter'", "/Users/apple/Desktop/logstash-6.2.2/logstash-core/lib/logstash/filters/base.rb:145:in `do_filter'", "/Users/apple/Desktop/logstash-6.2.2/logstash-core/lib/logstash/filters/base.rb:164:in`block in multi\_filter'", "org/jruby/RubyArray.java:1734:in `each'", "/Users/apple/Desktop/logstash-6.2.2/logstash-core/lib/logstash/filters/base.rb:161:in`multi\_filter'", "/Users/apple/Desktop/logstash-6.2.2/logstash-core/lib/logstash/filter\_delegator.rb:47:in `multi_filter'", "(eval):202:in`block in initialize'", "org/jruby/RubyArray.java:1734:in `each'", "(eval):198:in`block in initialize'", "(eval):148:in `block in filter_func'", "/Users/apple/Desktop/logstash-6.2.2/logstash-core/lib/logstash/pipeline.rb:447:in`filter\_batch'", "/Users/apple/Desktop/logstash-6.2.2/logstash-core/lib/logstash/pipeline.rb:426:in `worker_loop'", "/Users/apple/Desktop/logstash-6.2.2/logstash-core/lib/logstash/pipeline.rb:385:in`block in start\_workers'"], :class=\>"TypeError"}

And I noticed the example in the document, they usually do the match with "message", I am not sure if it is available for us to do the filter parsing with the specific field, like "geo\_information" in my case.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2018, 7:49pm UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/6 "2018-03-23T19:49:55Z")

</div>

Is that initial example a complete event/message?

---

<div class="post-metadata">

**Author:** ![Pororo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pororo/32/27711_2.png) [@Pororo](https://discuss.elastic.co/u/Pororo)\
**Post date:** [March 23, 2018, 7:51pm UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/7 "2018-03-23T19:51:26Z")

</div>

Nah, the complete message is  
{"geo\_information": "....", "name": ".....", "age": "......"}

Actually, my message is more complicated than this. For the clear visualization, I did the cutting of the whole message in this scenario.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 29, 2018, 5:10pm UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/8 "2018-03-29T17:10:40Z")

</div>

> [@Pororo](#):
>
> add\_filed

do you mean `add_field`?

> [@Pororo](#):
>
> "%{GREEDYDATA}%{NUMBER:lat:float}%{GREEDYDATA}%{NUMBER:lon:float}%{GREEDYDATA}"

I would advise coming up with a pattern that matches the shape of your data a little more explicitly; `GREEDYDATA` is very, very greedy (as the name implies), and you run the risk of it capturing more than you intend. If your pattern is always `:[` (latitude) `,` (longitude) `]`, we can get pretty specific _(note: the square brackets need to be prefixed by a backslash to escape them, since square brackets normally have special meaning in regular expressions and grok patterns)_:

```auto
":\[%{NUMBER:geo_lat:float},%{NUMBER:geo_lon:float}\]"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2018, 5:10pm UTC](https://discuss.elastic.co/t/geo-point-mapping/125105/9 "2018-04-26T17:10:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
