# Geo\_point

**URL:** <https://discuss.elastic.co/t/geo-point/48215>\
**Category:** Logstash\
**Created:** [April 23, 2016, 4:24am UTC](https://discuss.elastic.co/t/geo-point/48215 "2016-04-23T04:24:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![echua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/echua/32/9366_2.png) [@echua](https://discuss.elastic.co/u/echua)\
**Post date:** [April 23, 2016, 4:24am UTC](https://discuss.elastic.co/t/geo-point/48215/1 "2016-04-23T04:24:37Z")

</div>

I am trying to use the mapping portion of Kibana to map all the points that I have in my database for a given time period. I just started ELK so I don't know a lot. I have been struggling to insert geo\_point type of data into elastic 2.3 from logstash. My Kibana 4.5 doesn't seem to be able to recognize the points as geo points and when I try to select objects, nothing shows up in the tile maps. Here is my logstash configs. I am using the standard mappings that came with the application. HELP! Any suggestions would be appreciated. I believe I need to create a type of geo\_point.

# file: simple-out.conf

input {  
jdbc {  
# Postgres jdbc connection string to our database, mydb  
jdbc\_connection\_string =\> "jdbc:oracle:thin:@[//192.168.229.129:1521/XE](https://192.168.229.129:1521/XE)"  
# The user we wish to execute our statement as  
jdbc\_user =\> "dev"  
jdbc\_password =\> "dev"  
jdbc\_validate\_connection =\> true  
# The path to our downloaded jdbc driver  
jdbc\_driver\_library =\> "/home/siteadm/lib/ojdbc6-11.2.0.1.0.jar"  
# The name of the driver class for oracle  
jdbc\_driver\_class =\> "Java::oracle.jdbc.OracleDriver"  
#schedule =\> "0 \* \* \* \* "  
# our query  
statement =\> "SELECT [r.id](http://r.id) as request\_id, r.tfpsysid as tfpsysid, r.central\_tfpsys\_id as central\_tfpsys\_id, r.tfpsys\_location\_title as financial\_institution, r.tfpsys\_location\_address\_line1 as fi\_address, r.tfpsys\_location\_city as fi\_city, r.tfpsys\_location\_state\_code as fi\_state, r.tfpsys\_location\_zip as fi\_zip, t.latitude as latitude, t.longitude as longitude from requests r inner join tfpsys\_locations t on [r.tfpsysid=t.id](http://r.tfpsysid=t.id) where r.updated\_date \> sysdate-10"  
}  
}  
filter {  
if [latitude] and [longitude] {  
mutate {  
add\_field =\> ["[location]", "%{longitude}" ]  
add\_field =\> ["[location]", "%{latitude}" ]  
}  
}  
mutate {  
convert =\> ["[location]", "float" ]  
}

}

output {  
elasticsearch {  
hosts =\> localhost  
}  
stdout { codec =\> dots }

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2016, 5:36pm UTC](https://discuss.elastic.co/t/geo-point/48215/2 "2016-04-24T17:36:25Z")

</div>

If you inspect the mapping of an index in Elasticsearch I think you'll find something similar to this:

```auto
        "geoip" : {
          "dynamic": true,
          "properties" : {
            "ip": { "type": "ip" },
            "location" : { "type" : "geo_point" },
            "latitude" : { "type" : "float" },
            "longitude" : { "type" : "float" }
          }
        }

```

This tells us that the `geoip.location` field (`[geoip][location]` in Logstash notation) is a geo\_point field. I don't think you'll find anything similar about the `location` field that you're currently using. So, adjust what your messages look like or change the index template so that the `location` field is also mapped as geo\_point.

---

<div class="post-metadata">

**Author:** ![echua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/echua/32/9366_2.png) [@echua](https://discuss.elastic.co/u/echua)\
**Post date:** [April 24, 2016, 6:58pm UTC](https://discuss.elastic.co/t/geo-point/48215/3 "2016-04-24T18:58:22Z")

</div>

I am trying to do that and I guess I just don't understand enough how to map it. I was trying to use the filter. Can you point me in the right direction? How would my filter change?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2016, 8:24pm UTC](https://discuss.elastic.co/t/geo-point/48215/4 "2016-04-24T20:24:26Z")

</div>

I suppose

```nohighlight
mutate {
  add_field => ["[geoip][location]", "%{longitude}" ]
  add_field => ["[geoip][location]", "%{latitude}" ]
}

```

would work. Or, again, if you have no need for the `geoip` parent field you might want to change your mappings instead.

---

<div class="post-metadata">

**Author:** ![echua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/echua/32/9366_2.png) [@echua](https://discuss.elastic.co/u/echua)\
**Post date:** [April 25, 2016, 3:14am UTC](https://discuss.elastic.co/t/geo-point/48215/5 "2016-04-25T03:14:29Z")

</div>

Thank you! Just had to add the conversion to float and it works!

mutate {  
add\_field =\> ["[geoip][location]","%{longitude}"]  
add\_field =\> ["[geoip][location]","%{latitude}"]  
}

```
    mutate {
            convert => ["[geoip][location]", "float" ]
    }
```

---

<div class="post-metadata">

**Author:** ![echua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/echua/32/9366_2.png) [@echua](https://discuss.elastic.co/u/echua)\
**Post date:** [September 13, 2016, 4:39pm UTC](https://discuss.elastic.co/t/geo-point/48215/6 "2016-09-13T16:39:31Z")

</div>

To anyone that needs help. I also posted a template to elasticsearch

curl  
-XPUT localhost:9200/_template/atemplate\_index -d '  
{  
"template": "atemplate_-\*",

"settings": {

```
"index.refresh_interval":

```

"60s"

},

"mappings": {

```
"_default_": {

  "_all": {"enabled":

```

true, "omit\_norms": true},

```
  "dynamic_templates": [ {

    "message_field": {

      "match":

```

"message",

```
      "match_mapping_type":

```

"string",

```
      "mapping": {

        "type":

```

"string", "index": "analyzed",  
"omit\_norms": true

```
      }

    }

  }, {

    "string_fields": {

      "match": "*",

      "match_mapping_type":

```

"string",

```
      "mapping": {

        "type":

```

"string", "index": "analyzed",  
"omit\_norms": true,

```
        "fields": {

          "raw":

```

{"type": "string", "index":  
"not\_analyzed", "ignore\_above": 256}

```
        }

      }

    }

  } ],

  "properties": {

    "@version": {

```

"type": "string", "index":  
"not\_analyzed" },

```
    "name": {"type":

```

"string"},

```
    "lonlat": { "type":

```

"geo\_point" }  
}  
}  
}  
}  
'

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:38am UTC](https://discuss.elastic.co/t/geo-point/48215/7 "2017-07-06T04:38:42Z")

</div>


