# Geoip is not generate .location

**URL:** https://discuss.elastic.co/t/geoip-is-not-generate-location/90951
**Category:** Logstash
**Created:** [June 27, 2017, 11:41am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951 "2017-06-27T11:41:29Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 27, 2017, 11:41am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/1 "2017-06-27T11:41:29Z")

</div>

Good morning,

I'm working with ELK for Palo Alto and I wanna to make an update from normal charts to Map Chart.

I've read different tutorials but it's not working properly

Logstash filter

if [SourceAddress] and [SourceAddress] !~ "(^127.0.0.1)|(^10.)|(^172.1[6-9].)|(^172.2[0-9].)|(^172.3[0-1].)|(^192.168.)|(^169.254.)" {  
geoip {  
database =\> "/etc/logstash/GeoLite2.mmdb"  
source =\> "SourceAddress"  
target =\> "SourceGeo"  
}

if [DestinationAddress] and [DestinationAddress] !~ "(^127.0.0.1)|(^10.)|(^172.1[6-9].)|(^172.2[0-9].)|(^172.3[0-1].)|(^192.168.)|(^169.254.)" {  
geoip {  
database =\> "/etc/logstash/GeoLite2.mmdb"  
source =\> "SourceAddress"  
target =\> "SourceGeo"  
}

It generates the location.lat and location. lan but not the

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b220df708c308b887aedf5ff58aca74f056d067b.JPG)

Any ideas why the location is not working ok?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 27, 2017, 12:08pm UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/2 "2017-06-27T12:08:03Z")

</div>

Both your filters use `SourceAddress` to populate `SourceGeo`. Looks like you need to change this to `DestinationAddress` and `DestinationGeo` in the second one?

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 27, 2017, 12:12pm UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/3 "2017-06-27T12:12:11Z")

</div>

I've got a wrong in the copy paste.

the real state is the following

if [SourceAddress] and [SourceAddress] !~ "(^127.0.0.1)|(^10.)|(^172.1[6-9].)|(^172.2[0-9].)|(^172.3[0-1].)|(^192.168.)|(^169.254.)" {  
geoip {  
database =\> "/etc/logstash/GeoLite2.mmdb"  
source =\> "SourceAddress"  
target =\> "SourceGeo"  
}

}  
#Geolocate logs that have DestinationAddress and if that DestinationAddress is a non-RFC1918 address  
if [DestinationAddress] and [DestinationAddress] !~ "(^127.0.0.1)|(^10.)|(^172.1[6-9].)|(^172.2[0-9].)|(^172.3[0-1].)|(^192.168.)|(^169.254.)" {  
geoip {  
database =\> "/etc/logstash/GeoLite2.mmdb"  
source =\> "DestinationAddress"  
target =\> "DestinationGeo"  
}  
}

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 27, 2017, 12:16pm UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/4 "2017-06-27T12:16:06Z")

</div>

Have you uploaded an index template that maps these fields correctly as a `geo_point`?

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 27, 2017, 12:18pm UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/5 "2017-06-27T12:18:26Z")

</div>

hi Christian,

I'm delete the index and regenerate in kibana but I dont know if it is the same.

I'm a bit newbie with ELK

regards

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 27, 2017, 12:21pm UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/6 "2017-06-27T12:21:02Z")

</div>

The default index template for the `logstash-*` indices maps the field `geoip.location` as a `geo_point` as shown [here](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es5x.json#L38). In order for your fields to be recognised as a geo\_point, you need to create/update the index template to map your fields the same way.

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 27, 2017, 12:29pm UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/7 "2017-06-27T12:29:31Z")

</div>

hi again,

maybe it's a stupid question but Where I've to set this file? and which permissions?

many thanks!!

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 27, 2017, 2:00pm UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/8 "2017-06-27T14:00:52Z")

</div>

I've installed the template and logstash is working properly

> [2017-06-27T15:43:53,520][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword"}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
> [2017-06-27T15:43:53,528][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::Elasticsearch", :hosts=\>[#\<URI::Generic:0x653850cb URL://localhost:9200\>]}  
> [2017-06-27T15:43:53,639][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}

Create the index pam-traffic but the geoip value doesnt appear

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa64884117e6af1129c304fcd48171979089ad9b.JPG)

any idea?

---

<div class="post-metadata">

### Author: ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)
#### Post date: [June 28, 2017, 1:40am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/9 "2017-06-28T01:40:33Z")

</div>

I think u need add some field to index-template . it look like

> PUT /\_template/index-template-name  
> {  
> "properties": {  
> "SourceGeo": {  
> "type": "geo\_point"  
> }  
> }  
> }

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 28, 2017, 6:50am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/10 "2017-06-28T06:50:34Z")

</div>

Copy the [default Logstash index template](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es5x.json#L38) and modify the `template` field in it to match your index name. Then add mappings for `SourceGeo.location` and `DestinationGeo.location` similar to how `geoip.location` is mapped. You can then either upload this template manually, e.g. using curl, or instruct Logstash to do so for you using the [template](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template) parameter in the elasticsearch output plugin.

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 28, 2017, 7:30am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/11 "2017-06-28T07:30:00Z")

</div>

Many thanks.

1. I find that the template that i've deployed in /etc/logstasth/elasticsearch-template.json is not included in logstashs

2. the log when logstash starts is the following:

As you can see the version is 50001 but I've modify this value to identify if the correct template is loaded or not into the platform

Command line to get the template loaded

```
curl -XGET 'http://localhost:9200/_template/'
{"logstash":{"order":0,"version":50001,"template":"logstash-*","settings":{"index":{"refresh_interval":"5s"}},"mappings":{"_default_":{"dynamic_templates":[{"message_field":{"path_match":"message","mapping":{"norms":false,"type":"text"},"match_mapping_type":"string"}},{"string_fields":{"mapping":{"norms":false,"type":"text","fields":{"keyword":{"type":"keyword"}}},"match_mapping_type":"string","match":"*"}}],"_all":{"norms":false,"enabled":true},"properties":{"@timestamp":{"include_in_all":false,"type":"date"},"geoip":{"dynamic":true,"properties":{"ip":{"type":"ip"},"latitude":{"type":"half_float"},"location":{"type":"geo_point"},"longitude":{"type":"half_float"}}},"@version":{"include_in_all":false,"type":"keyword"}}}},"aliases":{}}}

```

1. Where is this default template? or how can i change it?

kindly regards

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 28, 2017, 8:25am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/12 "2017-06-28T08:25:33Z")

</div>

> [@legolas\_bilbao](#):
>
> "template" : "logstash-\*",

You need to change this pattern to match your index and store it using a different [name](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template_name).

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 28, 2017, 10:09am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/13 "2017-06-28T10:09:46Z")

</div>

What I did:

```
curl -XGET 'localhost:9200/_template?pretty'
{
  "logstash" : {
    "order" : 0,
    "version" : 50001,
    "template" : "logstash-*",
    "settings" : {
      "index" : {
        "refresh_interval" : "5s"
      }
    },
    "mappings" : {
      "_default_" : {
        "dynamic_templates" : [
          {
            "message_field" : {
              "path_match" : "message",
              "mapping" : {
                "norms" : false,
                "type" : "text"
              },
              "match_mapping_type" : "string"
            }
          },
          {
            "string_fields" : {
              "mapping" : {
                "norms" : false,
                "type" : "text",
                "fields" : {
                  "keyword" : {
                    "type" : "keyword"
                  }
                }
              },
              "match_mapping_type" : "string",
              "match" : "*"
            }
          }
        ],
        "_all" : {
          "norms" : false,
          "enabled" : true
        },
        "properties" : {
          "@timestamp" : {
            "include_in_all" : false,
            "type" : "date"
          },
          "geoip" : {
            "dynamic" : true,
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "location" : {
                "type" : "geo_point"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "@version" : {
            "include_in_all" : false,
            "type" : "keyword"
          }
        }
      }
    },
    "aliases" : { }
  },
  "pan-traffic" : {
    "order" : 0,
    "version" : 2,
    "template" : "pan_traffic",
    "settings" : {
      "index" : {
        "refresh_interval" : "5s"
      }
    },
    "mappings" : {
      "_default_" : {
        "dynamic_templates" : [
          {
            "message_field" : {
              "mapping" : {
                "index" : "analyzed",
                "omit_norms" : true,
                "type" : "string"
              },
              "match_mapping_type" : "string",
              "match" : "message"
            }
          },
          {
            "string_fields" : {
              "mapping" : {
                "index" : "analyzed",
                "omit_norms" : true,
                "type" : "string",
                "fields" : {
                  "raw" : {
                    "ignore_above" : 256,
                    "index" : "not_analyzed",
                    "type" : "string"
                  }
                }
              },
              "match_mapping_type" : "string",
              "match" : "*"
            }
          }
        ],
        "_all" : {
          "enabled" : true
        },
        "properties" : {
          "geoip" : {
            "dynamic" : true,
            "type" : "object",
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "location" : {
                "type" : "geo_point"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "@version" : {
            "index" : "not_analyzed",
            "type" : "string"
          }
        }
      }
    },
    "aliases" : { }
  }
}

```

I start again the ELK stack and add pan-traffic in kibana.

Search for GEOIP and the result is

 ![](https://us1.discourse-cdn.com/elastic/original/3X/5/9/594857cf5f848fbc5395d68870fdb2cbe18524cf.JPG)

I've upload the template with following command:

curl -XPUT '[http://localhost:9200/\_template/pan-traffic](http://localhost:9200/_template/pan-traffic)' -d@/etc/logstash/pantraffic-template.json

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 28, 2017, 10:53am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/14 "2017-06-28T10:53:52Z")

</div>

What does `pantraffic-template.json` look like? Once it is uploaded, I also think you need to delete and recreate your index, as index templates are applied at creation time.

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 28, 2017, 10:59am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/15 "2017-06-28T10:59:12Z")

</div>

Hi christian  
{  
"template" : "pan\_traffic",  
"version": 2,  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : true},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true  
}  
}  
}, {  
"string\_fields" : {  
"match" : "\*",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true,  
"fields" : {  
"raw" : {"type": "string", "index" : "not\_analyzed", "ignore\_above" : 256}  
}  
}  
}  
} ],  
"properties" : {  
"@version": { "type": "string", "index": "not\_analyzed" },  
"geoip" : {  
"type" : "object",  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" }, "location" : { "type" : "geo\_point" }, "latitude" : { "type" : "half\_float" }, "longitude" : { "type" : "half\_float" }  
}  
}  
}  
}  
}  
}

1. I've deleted the pan-index in kibana but the problem persists

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 28, 2017, 11:04am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/16 "2017-06-28T11:04:07Z")

</div>

This template does not seem to maintain the mapping required for your fields. You will also need to delete the indices from Elasticsearch and recreate them, not just the index patterns in Kibana.

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 28, 2017, 11:10am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/17 "2017-06-28T11:10:23Z")

</div>

Hi christian,

If I understand you fine the steps that I've to follow are the following

1 ) curl -XDELETE \<[http://localhost:9200/\_template/OldTemplateName](http://localhost:9200/_template/OldTemplateName)  
2) stop elastichsearch  
3) Delete pan-traffic index in kibana  
5 ) stop kibana  
6) start elasticsearch  
7) curl -XPUT '[http://localhost:9200/\_template/pan-traffic](http://localhost:9200/_template/pan-traffic)' -d@/etc/logstash/pantraffic-template.json  
8) start kibana  
9) Add the new index in kibana

is correct?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 28, 2017, 11:14am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/18 "2017-06-28T11:14:31Z")

</div>

I think the following should be sufficient:

1. Update pantraffic-template.json to contain mappings for your fields.
2. Push this template to the cluster, which should obverride the existing one.
3. Delete the pan-traffic index through the [delete index API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-delete-index.html)
4. Write data to the pan-traffic index
5. Refresh the mappings for the pan-traffic index pattern in Kibana

---

<div class="post-metadata">

### Author: ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)
#### Post date: [June 28, 2017, 11:17am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/19 "2017-06-28T11:17:42Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> 1. Update pantraffic-template.json to contain mappings for your fields

What do you mean with this?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 28, 2017, 11:19am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951/20 "2017-06-28T11:19:15Z")

</div>

It does not seem to contain mappings for `SourceGeo.location` and `DestinationGeo.location` so you need to add that.

[Next page](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951.md?page=2)
