# GeoIP Mapping in ES

**URL:** <https://discuss.elastic.co/t/geoip-mapping-in-es/142803>\
**Category:** Elasticsearch\
**Created:** [August 2, 2018, 7:52pm UTC](https://discuss.elastic.co/t/geoip-mapping-in-es/142803 "2018-08-02T19:52:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![casperhxr](https://avatars.discourse-cdn.com/v4/letter/c/c4cdca/32.png) [@casperhxr](https://discuss.elastic.co/u/casperhxr)\
**Post date:** [August 2, 2018, 7:52pm UTC](https://discuss.elastic.co/t/geoip-mapping-in-es/142803/1 "2018-08-02T19:52:18Z")

</div>

Hello All,

I currently have a working ElasticStack 6.3.0. I'm trying to set the mapping for a new GeoIP field. By default when I use the 'geoip' logstash filter everything works fine. I get a field called geoip.location that is a geo\_point type. The data I'm using has a destination and source IP. I'd like to map them both at the same time. This is what my logstash filter looks like:  
if [src\_ip] {  
geoip {  
source =\> "src\_ip"  
target =\> "src\_geoip"  
database =\> "/etc/logstash/GeoLite2-Xity.mmdb"  
}  
}  
if [dst\_ip] {  
geoip {  
source =\> "dst\_ip"  
target =\> "dst\_geoip"  
database =\> "/etc/logstash/GeoLite2-Xity.mmdb"  
}  
}  
The filter works fine and creates all the appropriate fields. However, the elasticsearch mapping template isn't setup to make src\_geoip and dst\_geoip a geo\_point type. I've noticed that in 6.3.0 the _default_ mapping is being deprecated. I'd like to know how I should correctly update my mapping to get these geo\_points.

This is my current mapping;  
curl -XGET [http://192.168.0.10:9200/\_template/logstash?pretty](http://192.168.0.10:9200/_template/logstash?pretty)  
{  
"logstash" : {  
"order" : 0,  
"version" : 60002,  
"index\_patterns" : [  
"logstash-_"  
],  
"settings" : {  
"index" : {  
"number\_of\_shards" : "2",  
"refresh\_interval" : "5s"  
}  
},  
"mappings" : {  
"default" : {  
"dynamic\_templates" : [  
{  
"message\_field" : {  
"path\_match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text",  
"norms" : false  
}  
}  
},  
{  
"string\_fields" : {  
"match" : "_",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text",  
"norms" : false,  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
}  
}  
}  
],  
"properties" : {  
"@timestamp" : {  
"type" : "date"  
},  
"@version" : {  
"type" : "keyword"  
},  
"geoip" : {  
"dynamic" : true,  
"properties" : {  
"ip" : {  
"type" : "ip"  
},  
"location" : {  
"type" : "geo\_point"  
},  
"latitude" : {  
"type" : "half\_float"  
},  
"longitude" : {  
"type" : "half\_float"  
}  
}  
},  
"src\_geoip" : {  
"dynamic" : true,  
"properties" : {  
"ip" : {  
"type" : "ip"  
},  
"location" : {  
"type" : "geo\_point"  
},  
"latitude" : {  
"type" : "half\_float"  
},  
"longitude" : {  
"type" : "half\_float"  
}  
}  
},  
"dst\_geoip" : {  
"dynamic" : true,  
"properties" : {  
"ip" : {  
"type" : "ip"  
},  
"location" : {  
"type" : "geo\_point"  
},  
"latitude" : {  
"type" : "half\_float"  
},  
"longitude" : {  
"type" : "half\_float"  
}  
}  
}  
}  
}  
},  
"aliases" : { }  
}  
}

I'm not that great with interpreting the elastic docs on json calls with curl. A clear and concise answer would be very much appreciated. If you need additional information please let me know.

Thank you!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 2, 2018, 10:21pm UTC](https://discuss.elastic.co/t/geoip-mapping-in-es/142803/2 "2018-08-02T22:21:07Z")

</div>

That looks ok from what I can tell. Your various location fields are mapped as geopoints for eg. Is something not working as you expect?

(Hint, in future please use the `</>` (code) button to format json like the pasted mappings, it makes it much easier to read 🙂 )

---

<div class="post-metadata">

**Author:** ![casperhxr](https://avatars.discourse-cdn.com/v4/letter/c/c4cdca/32.png) [@casperhxr](https://discuss.elastic.co/u/casperhxr)\
**Post date:** [August 2, 2018, 10:32pm UTC](https://discuss.elastic.co/t/geoip-mapping-in-es/142803/3 "2018-08-02T22:32:14Z")

</div>

Thank you for your quick response. (I'll use the formatting button next time)

I just realized that I needed to refresh the field list on the index pattern. After doing this the fields showed up correctly as geo\_points. haha I spent too much time on that haha.

Thank you again!

Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2018, 10:32pm UTC](https://discuss.elastic.co/t/geoip-mapping-in-es/142803/4 "2018-08-30T22:32:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
