# Geoip property into filebeat index template - help

**URL:** <https://discuss.elastic.co/t/geoip-property-into-filebeat-index-template-help/211197>\
**Category:** Elasticsearch\
**Created:** [December 9, 2019, 10:14pm UTC](https://discuss.elastic.co/t/geoip-property-into-filebeat-index-template-help/211197 "2019-12-09T22:14:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cdnvballer](https://avatars.discourse-cdn.com/v4/letter/c/da6949/32.png) [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Post date:** [December 9, 2019, 10:14pm UTC](https://discuss.elastic.co/t/geoip-property-into-filebeat-index-template-help/211197/1 "2019-12-09T22:14:06Z")

</div>

My elk setup leverages filebeats and logstash, based on [this](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-18-04)

Standard visualization runs and I was able to use logstash conditions to add  
[[geoip][location][latitude] and [geoip][location][longitude]](https://discuss.elastic.co/t/need-help-with-adding-geoip-to-syslog-and-then-how-to-visualize/209113/11) , with help from [here](https://discuss.elastic.co/t/if-statement-is-failing-to-match-for-certain-values-pls-help/210438/2)  
--\> all relevant events have these above fields added and populated with expected values =)

when I run " curl -XGET [http://127.0.0.1:9200/\_aliases?pretty=true](http://127.0.0.1:9200/_aliases?pretty=true) "  
I see the several filebeat-6.8.5-\<datestamp\> indexes.

can someone walk me through how I'm supposed to add the geoip property to my index mapping?  
I was told to look into index template, but I'm lost..  
reading into [what looks to be a logstash template with geoip](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json) and [this doc that goes over adding custom geoip field to filebeat](https://blog.barclayhowe.com/adding-a-custom-geoip-field-to-filebeat-and-elasticsearch-in-elk/)

not sure if all I need is to figure out how to add this section into template:

> "properties" : {  
> "geoip" : {  
> "dynamic": true,  
> "properties" : {  
> "ip": { "type": "ip" },  
> "location" : { "type" : "geo\_point" },  
> "latitude" : { "type" : "half\_float" },  
> "longitude" : { "type" : "half\_float" }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2020, 10:14pm UTC](https://discuss.elastic.co/t/geoip-property-into-filebeat-index-template-help/211197/2 "2020-01-06T22:14:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
