# Geoip's dotted fields and ES2.0

**URL:** https://discuss.elastic.co/t/geoips-dotted-fields-and-es2-0/32874
**Category:** Logstash
**Created:** [October 23, 2015, 6:03pm UTC](https://discuss.elastic.co/t/geoips-dotted-fields-and-es2-0/32874 "2015-10-23T18:03:08Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![renevdm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/renevdm/32/5730_2.png) [@renevdm](https://discuss.elastic.co/u/renevdm)
#### Post date: [October 23, 2015, 6:03pm UTC](https://discuss.elastic.co/t/geoips-dotted-fields-and-es2-0/32874/1 "2015-10-23T18:03:08Z")

</div>

In the [Logstash 2.0.0-rc1 released blog article](https://www.elastic.co/blog/logstash-2-0-0-rc1-released) I read:

"Elasticsearch does not allow field names to have dots, beginning with version 2.0".

So how about geoip? It adds dotted fields by default. I can imagine the plugin will have an update to create other kinds of fields, but how about the fields that are already indexed?

---

<div class="post-metadata">

### Author: ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)
#### Post date: [October 23, 2015, 6:23pm UTC](https://discuss.elastic.co/t/geoips-dotted-fields-and-es2-0/32874/2 "2015-10-23T18:23:49Z")

</div>

> [@renevdm](#):
>
> So how about geoip? It adds dotted fields by default.

It does? It does [nested fields](https://github.com/logstash-plugins/logstash-filter-geoip/blob/master/lib/logstash/filters/geoip.rb#L58-L69) in the current release, using the "target" field name as the parent field.

```
  # Specify the field into which Logstash should store the geoip data.
  # This can be useful, for example, if you have `src\_ip` and `dst\_ip` fields and
  # would like the GeoIP information of both IPs.
  #
  # If you save the data to a target field other than `geoip` and want to use the
  # `geo\_point` related functions in Elasticsearch, you need to alter the template
  # provided with the Elasticsearch output and configure the output to use the
  # new template.
  #
  # Even if you don't use the `geo\_point` mapping, the `[target][location]` field
  # is still valid GeoJSON.
  config :target, :validate => :string, :default => 'geoip'

```

When I look at the [fields available](https://github.com/logstash-plugins/logstash-filter-geoip/blob/master/lib/logstash/filters/geoip.rb#L48-L56), none have dots:

```
  # An array of geoip fields to be included in the event.
  #
  # Possible fields depend on the database type. By default, all geoip fields
  # are included in the event.
  #
  # For the built-in GeoLiteCity database, the following are available:
  # `city_name`, `continent_code`, `country_code2`, `country_code3`, `country_name`,
  # `dma_code`, `ip`, `latitude`, `longitude`, `postal_code`, `region_name` and `timezone`.
  config :fields, :validate => :array

```

---

<div class="post-metadata">

### Author: ![renevdm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/renevdm/32/5730_2.png) [@renevdm](https://discuss.elastic.co/u/renevdm)
#### Post date: [October 23, 2015, 8:30pm UTC](https://discuss.elastic.co/t/geoips-dotted-fields-and-es2-0/32874/3 "2015-10-23T20:30:58Z")

</div>

Oh are those nested fields? Sorry, I don't work that long with ELK, so I have to get into it and get used to the terminology. I thought because it looks like this:

geoip.city\_name Mountain View  
geoip.continent\_code NA  
geoip.coordinates -122.057, 37.419  
geoip.country\_code2 US  
geoip.country\_code3 USA  
geoip.country\_name United States

because of the dots, it's a dotted field. I had no clue it were nested fields. Never too old to learn 🙂 Thanks for the clarification! (and it's a relief also, I was afraid I had to rename fields and rebuild indexes....)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/geoips-dotted-fields-and-es2-0/32874/4 "2017-07-06T05:25:34Z")

</div>


