Based on the documentation, geo_point should be in geoip.location. But in Elastic I see fields geoip.location.lat and geoip.location.lon. Here is my part of the document:
If you can't make it work, could you provide a full recreation script as described in About the Elasticsearch category. It will help to better understand what you are doing. Please, try to keep the example as simple as possible.
A full reproduction script will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.
There is no script at all. Just receiving logs from Filebeats and Logstash is parsing them. After that I get a field named source_ip, which contains IP (IPv6 or IPv4), I do get GeoIP data with this field:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.