# Geoip conflict when splitting the index by day

**URL:** <https://discuss.elastic.co/t/geoip-conflict-when-splitting-the-index-by-day/263226>\
**Category:** Kibana\
**Created:** [February 4, 2021, 10:00am UTC](https://discuss.elastic.co/t/geoip-conflict-when-splitting-the-index-by-day/263226 "2021-02-04T10:00:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![testsoft](https://avatars.discourse-cdn.com/v4/letter/t/e19adc/32.png) [@testsoft](https://discuss.elastic.co/u/testsoft)\
**Post date:** [February 4, 2021, 10:00am UTC](https://discuss.elastic.co/t/geoip-conflict-when-splitting-the-index-by-day/263226/1 "2021-02-04T10:00:51Z")

</div>

## Good afternoon. Please help with the following question. I use the following standard output config:

```
    elasticsearch {
            hosts => ["localhost:9200"]
            manage_template => false
            index => "syslog-%{+YYYY.MM.dd}"
}

```

* * *

## In Logstash filter:

```
	geoip {
		source => "[http][access][remote_addr]"
		target => "[geoip]"
	}

```

* * *

I create field geoip in syslog-\*. Everything works well and I can use the geo map in Kibana, but only until a new day comes. After a new file with a different date appears, the field conflict occurs (pictures in attach):

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a944c0138300833fb8f37b67157238a225bb946e.png)

 ![Capture2](https://us1.discourse-cdn.com/elastic/original/3X/3/5/350a5feb846a324c87e4514b7a1e7a391499d258.png)

please help solve this problem, thank you.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [February 4, 2021, 4:14pm UTC](https://discuss.elastic.co/t/geoip-conflict-when-splitting-the-index-by-day/263226/2 "2021-02-04T16:14:29Z")

</div>

Do you have any index templates set up for `syslog-*`? You may need to set up an index template [1] to ensure that new indices are mapping the field as IP rather than objects.

[1] [Index templates | Elasticsearch Reference [7.10] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/index-templates.html)

---

<div class="post-metadata">

**Author:** ![testsoft](https://avatars.discourse-cdn.com/v4/letter/t/e19adc/32.png) [@testsoft](https://discuss.elastic.co/u/testsoft)\
**Post date:** [February 5, 2021, 7:27am UTC](https://discuss.elastic.co/t/geoip-conflict-when-splitting-the-index-by-day/263226/3 "2021-02-05T07:27:20Z")

</div>

Thank You for help, it works!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2021, 7:27am UTC](https://discuss.elastic.co/t/geoip-conflict-when-splitting-the-index-by-day/263226/4 "2021-03-05T07:27:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
