# GeoIP doesn't work on ELK stack

**URL:** <https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815>\
**Category:** Elasticsearch\
**Created:** [October 13, 2017, 4:03am UTC](https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815 "2017-10-13T04:03:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 13, 2017, 4:03am UTC](https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815/1 "2017-10-13T04:03:46Z")

</div>

Hi there,  
Im using ELK stack to parse nginx log and visualize it on Kibana with geoip on Codinate map.  
But i got the error as below when using Elasticsearch version 5.5.2, but not Elasticsearch version 5.4.1:  
`No Compatible Fields: The "filebeat-*" index pattern does not contain any of the following field types: geo_point`

In ES ver 5.4.1:

> ```
> "geoip" : {
> "properties" : {
> "continent_name" : {
> "type" : "keyword",
> "ignore_above" : 1024
> },
> "country_iso_code" : {
> "type" : "keyword",
> "ignore_above" : 1024
> },
> "location" : {
> "type" : "geo_point"
> }
> }
> },
> 
> ```

In ES ver 5.5.2, i can't find value "geo\_point", also field "location"

Could someone help me to understand for this case?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 13, 2017, 5:04am UTC](https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815/2 "2017-10-13T05:04:28Z")

</div>

FYI we’ve renamed ELK to the Elastic Stack, otherwise Beats feels left out 😉

Did you do an upgrade, or is this a separate stack? Is that code the mapping? What does the 5.5.2 mapping look like? What does your filebeat config look like?

---

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 13, 2017, 8:00am UTC](https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815/3 "2017-10-13T08:00:38Z")

</div>

The following is my logstash configuration:

```
input {
	beats {
	       port => 5044
	       client_inactivity_timeout => 120
	}
}
filter {
	grok {
		match => {
			"message" => '%{IPORHOST:node_elk_ip} - - \[%{HTTPDATE:[request_info][time]}\] "%{WORD:[request_info][method]} %{DATA:[request_info][API]} HTTP/%{NUMBER:[request_info][http_version]}" %{NUMBER:[request_info][response_status]} %{NUMBER:[request_info][bytes]} "%{DATA:[request_info][referrer]}" "%{DATA:agent}" "%{IP:[user_request][user_IP]}" "%{NUMBER:[user_request][request_time]}" "%{DATA:[user_request][upstream_response_time]}" "%{DATA:[user_request][user_role]}"'
		}
		remove_field => "message"
	}

	geoip {
		source => "[user_request][user_IP]"
		target => "geoip"
	}
	useragent {
		source => "agent"
		target => "user_agent"
		remove_field => "agent"
	}
    
}
output {
	#stdout { codec => rubydebug }
	elasticsearch {
		hosts => ["localhost:9200"]
		#sniffing => true
		manage_template => false
		index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
		document_type => "%{[@metadata][type]}"
	}
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 13, 2017, 9:46am UTC](https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815/4 "2017-10-13T09:46:00Z")

</div>

Can you share a typical document that is indexed in elasticsearch?

---

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [November 2, 2017, 9:11am UTC](https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815/5 "2017-11-02T09:11:57Z")

</div>

This issue was resoleved. I changed index from "%{[@metadata][beat]}-%{+YYYY.MM.dd}" to "logstash-%{+YYYY.MM.dd}".

Thank you .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2017, 9:12am UTC](https://discuss.elastic.co/t/geoip-doesnt-work-on-elk-stack/103815/6 "2017-11-30T09:12:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
