# Geoip.location not getting mapped to a geo\_point type

**URL:** <https://discuss.elastic.co/t/geoip-location-not-getting-mapped-to-a-geo-point-type/78625>\
**Category:** Elasticsearch\
**Created:** [March 15, 2017, 12:57am UTC](https://discuss.elastic.co/t/geoip-location-not-getting-mapped-to-a-geo-point-type/78625 "2017-03-15T00:57:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [March 15, 2017, 12:57am UTC](https://discuss.elastic.co/t/geoip-location-not-getting-mapped-to-a-geo-point-type/78625/1 "2017-03-15T00:57:25Z")

</div>

OS: CentOS 7.2.1511 - 3.10.0-327.22.2.el7.x86\_64  
ES version: elasticsearch-5.1.1  
Kibana version: kibana-5.1.1  
Logstash version: logstash-5.1.1

I looked at my default template (es-server:9200/\_template) and it shows geoip.location getting mapped to a geo\_point type:  
{  
"logstash": {  
"order": 0,  
"version": 50001,  
"template": "logstash-_",  
"settings": {  
"index": {  
"refresh\_interval": "5s"  
}  
},  
"mappings": {  
"default": {  
"dynamic\_templates": [  
{  
"message\_field": {  
"path\_match": "message",  
"mapping": {  
"norms": false,  
"type": "text"  
},  
"match\_mapping\_type": "string"  
}  
},  
{  
"string\_fields": {  
"mapping": {  
"norms": false,  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword"  
}  
}  
},  
"match\_mapping\_type": "string",  
"match": "_"  
}  
}  
],  
"\_all": {  
"norms": false,  
"enabled": true  
},  
"properties": {  
"@timestamp": {  
"include\_in\_all": false,  
"type": "date"  
},  
"geoip": {  
"dynamic": true,  
"properties": {  
"ip": {  
"type": "ip"  
},  
"latitude": {  
"type": "half\_float"  
},  
"location": {  
"type": "geo\_point"  
},  
"longitude": {  
"type": "half\_float"  
}  
}  
},  
"@version": {  
"include\_in\_all": false,  
"type": "keyword"  
}  
}  
}  
},  
"aliases": {}  
}  
}

I have this in my logstash config to filter geolocation:  
geoip {  
source =\> "MyFieldWithAnIP"  
}

So if I look in my ES index I can see its processing geo location on that field. For docs that logstash sends it I do see geoip data in them, here is an example of a geoip field from one of those documents:  
"geoip": {  
"city\_name": "Ibarra",  
"timezone": "America/Guayaquil",  
"ip": "181.198.183.74",  
"latitude": 0.35,  
"country\_code2": "EC",  
"country\_name": "Ecuador",  
"continent\_code": "SA",  
"country\_code3": "EC",  
"region\_name": "Provincia de Imbabura",  
"location": [  
-78.1167,  
0.35  
],

But if I go into kibana and try to create a map visualization from that index I get this:  
"error: No Compatible Fields: The "my\_index\_pattern" index pattern does not contain any of the following field types: geo\_point"

When I look at the index pattern I created in kibana the "type" of the geoip.location field is "number".

So I don't know where the break down is here. Is the default mapping not working? Did I misconfigure kibana?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [March 15, 2017, 2:09am UTC](https://discuss.elastic.co/t/geoip-location-not-getting-mapped-to-a-geo-point-type/78625/2 "2017-03-15T02:09:53Z")

</div>

> [@red888](#):
>
> "error: No Compatible Fields: The "my\_index\_pattern" index pattern does not contain any of the following field types: geo\_point"

The answer lies between `"template": "logstash-*",` as the pattern to match in the default template, and `my_index_pattern` in the error message. It would seem that you are creating indices that are _not_ named `logstash-`something, which is required for the index template to be applied.

---

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [March 15, 2017, 2:44am UTC](https://discuss.elastic.co/t/geoip-location-not-getting-mapped-to-a-geo-point-type/78625/3 "2017-03-15T02:44:29Z")

</div>

ahhh so obvious! Didn't understand enough about how mapping works, I thought this was like a default template applied to everything, I realize how little sense that makes now.

So I should be able to just do `geoip { source => "MyFieldWithAnIP" }` without any extra settings.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2017, 2:44am UTC](https://discuss.elastic.co/t/geoip-location-not-getting-mapped-to-a-geo-point-type/78625/4 "2017-04-12T02:44:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
