# Geoip field scope seperator is "." and not supported as mapping name

**URL:** <https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723>\
**Category:** Elasticsearch\
**Created:** [January 2, 2018, 5:30am UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723 "2018-01-02T05:30:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pelesmk](https://avatars.discourse-cdn.com/v4/letter/p/8e7dd6/32.png) [@pelesmk](https://discuss.elastic.co/u/pelesmk)\
**Post date:** [January 2, 2018, 5:30am UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723/1 "2018-01-02T05:30:04Z")

</div>

I'm using the geoip mapping and everything seems fine, except the geoip ends up using a . as the seperator, example geoip.location, geoip.city\_name, geoip.country\_name. The period is not supported and the error message is  
"reason"=\>"Field name [remote\_location.city] cannot contain '.'"}}}}

This makes sense and all of my other mappings don't contain periods. I think i read the period isnt supported in ES 2.x, so my question is, how do I rename the geoip seperator? My mappings are correct as shown below, but I don't know how to tell logstash not to use the "." as the field name, but to use something like an \_ underscore. I've tried the mutate and gsub, but don't really know how to use them in this context or if this is the correct context to use mutate gsub.

```
      "geoip" : {
        "properties" : {
          "city_name" : {
            "type" : "string"
          },
          "continent_code" : {
            "type" : "string"
          },
          "country_code2" : {
            "type" : "string"
          },
          "country_code3" : {
            "type" : "string"
          },
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 2, 2018, 6:42am UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723/2 "2018-01-02T06:42:57Z")

</div>

Apparently you renamed the target field to be "remote\_location", no?

If so you need to define it in your mapping accordingly.

---

<div class="post-metadata">

**Author:** ![pelesmk](https://avatars.discourse-cdn.com/v4/letter/p/8e7dd6/32.png) [@pelesmk](https://discuss.elastic.co/u/pelesmk)\
**Post date:** [January 2, 2018, 7:10pm UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723/3 "2018-01-02T19:10:12Z")

</div>

thanks for your reply David. I didn't rename remote\_location from "remote.location", but even if i did the problem would be even greater as the "." in "remote.location" wouldn't be supported by ES 2.x  
[https://www.elastic.co/guide/en/elasticsearch/reference/2.4/dots-in-names.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/dots-in-names.html)

Actually, I just read more carefully and it looks like in 2.4.x there's a system property to enable support called mapper.allow\_dots\_in\_name

I'm running 2.4.6, I'm gonna give that property setting a test.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 2, 2018, 7:53pm UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723/4 "2018-01-02T19:53:28Z")

</div>

It is supported if you define the correct mapping.

Where basically remote is an object and location is a field.

---

<div class="post-metadata">

**Author:** ![pelesmk](https://avatars.discourse-cdn.com/v4/letter/p/8e7dd6/32.png) [@pelesmk](https://discuss.elastic.co/u/pelesmk)\
**Post date:** [January 3, 2018, 12:40am UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723/5 "2018-01-03T00:40:59Z")

</div>

no luck, maybe it's only a 2.4.0 field? 2.4.6 says the property doesn't exist for mapper.allow\_dots\_in\_name. I'm going to investigate my other logstash installs to see if remote\_location has a different name there. The thing is, I only used remote\_location as an example here, but all of the geoip fields use a "." period separator, so it's not something I renamed. I did rename other fields/mappings to work around the period and those work correctly, just the geoip, which isn't something controlled by me as it's a properties thing \*I think

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 3, 2018, 6:33am UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723/6 "2018-01-03T06:33:04Z")

</div>

Can you reproduce this with a simple elasticsearch pure script (without logstash)?

Like:

- delete index
- create index with mapping
- index a doc

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2018, 6:37am UTC](https://discuss.elastic.co/t/geoip-field-scope-seperator-is-and-not-supported-as-mapping-name/113723/7 "2018-01-31T06:37:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
