# Geo\_point not working

**URL:** <https://discuss.elastic.co/t/geo-point-not-working/54082>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [June 27, 2016, 9:25pm UTC](https://discuss.elastic.co/t/geo-point-not-working/54082 "2016-06-27T21:25:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ALa](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@ALa](https://discuss.elastic.co/u/ALa)\
**Post date:** [June 27, 2016, 9:25pm UTC](https://discuss.elastic.co/t/geo-point-not-working/54082/1 "2016-06-27T21:25:36Z")

</div>

I'm using the beats-dashboards and I was trying to make client locations works  
the problem is as following:  
geoip.location field in packetbeat index is from type number, however in logstash index is the type of geoip.location geo\_point.  
any suggestions?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 28, 2016, 11:02am UTC](https://discuss.elastic.co/t/geo-point-not-working/54082/2 "2016-06-28T11:02:21Z")

</div>

Not sure I understand your question to 100%. What kind of data do you have in your logstash index?

---

<div class="post-metadata">

**Author:** ![ALa](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@ALa](https://discuss.elastic.co/u/ALa)\
**Post date:** [June 28, 2016, 2:24pm UTC](https://discuss.elastic.co/t/geo-point-not-working/54082/3 "2016-06-28T14:24:39Z")

</div>

the logstash index collects the data from filebeats.  
the point is, the type of geoip.location is correct in the logstash index (geo\_point) however in the packetbeat index the type is shown as (number).  
what is odd at this point is that I am not using geoip.location in any of logstash output to logstash index, I'm only using this field to output to the packetbeat index.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 28, 2016, 3:45pm UTC](https://discuss.elastic.co/t/geo-point-not-working/54082/4 "2016-06-28T15:45:16Z")

</div>

If you are going to enrich events with geo\_point data using Logstash's geoip filter then you need to customize the index template for your index so that the field mappings are correct. The provided index template for Packetbeat does not specify field named `geoip` that is a `geo_point`, but the [provided index template from Logstash does](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template.json#L34-L42).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2016, 9:25pm UTC](https://discuss.elastic.co/t/geo-point-not-working/54082/5 "2016-07-18T21:25:47Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
