# Geopoint failed to setup after upgrading to 5.6

**URL:** <https://discuss.elastic.co/t/geopoint-failed-to-setup-after-upgrading-to-5-6/101541>\
**Category:** Kibana\
**Created:** [September 22, 2017, 9:04pm UTC](https://discuss.elastic.co/t/geopoint-failed-to-setup-after-upgrading-to-5-6/101541 "2017-09-22T21:04:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![imortalsolitude](https://avatars.discourse-cdn.com/v4/letter/i/6f9a4e/32.png) [@imortalsolitude](https://discuss.elastic.co/u/imortalsolitude)\
**Post date:** [September 22, 2017, 9:04pm UTC](https://discuss.elastic.co/t/geopoint-failed-to-setup-after-upgrading-to-5-6/101541/1 "2017-09-22T21:04:34Z")

</div>

After upgrading ELK to 5.6 and upgrading the plugins geo-ip fails to add geo\_point and hence location cannot be visualized. Uninstalled and reinstalled geo-ip the geoip is being rendered on Kibana dashboard and is being passed in to the index as well but keep getting error message "index pattern does not contain any of the following field types: geo\_point" . Here's my logstash config

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp}%{SPACE}%{USERNAME}%{SPACE}%{IP}%{SPACE}%{SYSLOGTIMESTAMP}%{SPACE}%{HOSTNAME:hostname}%{SPACE}%{SYSLOGPROG}%{SPACE}%{WORD}%{NOTSPACE}%{SPACE}%{WORD}%{SPACE}%{WORD}%{SPACE}%{IP:src\_ip}/%{INT:src\_port}-\>%{IP:dest\_ip}/%{INT:dest\_port}%{SPACE}%{GREEDYDATA}"]  
}  
if "\_grokparsefailure" in [tags] { drop {} }  
date {  
match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss"]  
}  
geoip {  
source =\> "dest\_ip"  
target =\> "geoip"  
database =\> "/usr/share/logstash/plugins/data/GeoLite2-City.mmdb"  
}  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "index-%{type}-%{+YYYY.MM.dd}"  
user =\> elastic  
password =\> xxxxx

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [September 23, 2017, 12:07am UTC](https://discuss.elastic.co/t/geopoint-failed-to-setup-after-upgrading-to-5-6/101541/2 "2017-09-23T00:07:41Z")

</div>

Can you provide the mapping for your index? Example: `http://localhost:9200/logstash-*/_mapping`

---

<div class="post-metadata">

**Author:** ![imortalsolitude](https://avatars.discourse-cdn.com/v4/letter/i/6f9a4e/32.png) [@imortalsolitude](https://discuss.elastic.co/u/imortalsolitude)\
**Post date:** [September 25, 2017, 2:04pm UTC](https://discuss.elastic.co/t/geopoint-failed-to-setup-after-upgrading-to-5-6/101541/3 "2017-09-25T14:04:18Z")

</div>

Here's my mapping for Syslog Index

"index-syslog-2017.09.25" : {  
"mappings" : {  
"syslog" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date"  
},  
"@version" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"beat" : {  
"properties" : {  
"hostname" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"name" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"version" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
}  
}  
},  
"dest\_ip" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"dest\_port" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"geoip" : {  
"properties" : {  
"city\_name" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"continent\_code" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"country\_code2" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"country\_code3" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"country\_name" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"dma\_code" : {  
"type" : "long"  
},  
"ip" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"latitude" : {  
"type" : "float"  
},  
"location" : {  
"properties" : {  
"lat" : {  
"type" : "float"  
},  
"lon" : {  
"type" : "float"  
}  
}  
},  
"longitude" : {  
"type" : "float"  
},  
"postal\_code" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"region\_code" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"region\_name" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"timezone" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}

Here the data from the index that has a geoip information

root@ELK:~# curl -XGET '10.1.0.175:9200/index-syslog-2017.09.25/\_search?pretty&q=response=500'

{  
"\_index" : "index-syslog-2017.09.25",  
"\_type" : "syslog",  
"\_id" : "AV6qrLR13NU9fecMNbhW",  
"\_score" : 10.947816,  
"\_source" : {  
"geoip" : {  
"timezone" : "America/Los\_Angeles",  
"ip" : "151.101.188.193",  
"latitude" : 37.7697,  
"continent\_code" : "NA",  
"city\_name" : "San Francisco",  
"country\_name" : "United States",  
"country\_code2" : "US",  
"dma\_code" : 807,  
"country\_code3" : "US",  
"region\_name" : "California",  
"location" : {  
"lon" : -122.3933,  
"lat" : 37.7697  
},  
"postal\_code" : "94107",  
"region\_code" : "CA",  
"longitude" : -122.3933  
},  
"offset" : 14233922,  
"input\_type" : "log",  
"source" : "D:\Syslog\

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2017, 2:04pm UTC](https://discuss.elastic.co/t/geopoint-failed-to-setup-after-upgrading-to-5-6/101541/4 "2017-10-23T14:04:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
