# Getting GeoIP field for NGINX Logs

**URL:** <https://discuss.elastic.co/t/getting-geoip-field-for-nginx-logs/237903>\
**Category:** Logstash\
**Created:** [June 20, 2020, 8:00am UTC](https://discuss.elastic.co/t/getting-geoip-field-for-nginx-logs/237903 "2020-06-20T08:00:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaysbeekay](https://avatars.discourse-cdn.com/v4/letter/j/ecb155/32.png) [@jaysbeekay](https://discuss.elastic.co/u/jaysbeekay)\
**Post date:** [June 20, 2020, 8:00am UTC](https://discuss.elastic.co/t/getting-geoip-field-for-nginx-logs/237903/1 "2020-06-20T08:00:30Z")

</div>

Hi,

I am having trouble trying to get the location from NGINX logs to be shown as a GeoIP (instead of a float) within Kibana to visualise on a dashboard

I am currently filebeats to ship logs from my NGINX server to Logstash for processing. My Logstash configuration file looks like this:

```auto
   input {
        beats {
            host => "0.0.0.0"
            port => 5044
        }
    }

    filter {
     grok {
       match => ["message" , "%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra_fields}"]
       overwrite => ["message"]
     }
     mutate {
       convert => ["response", "integer"]
       convert => ["bytes", "integer"]
       convert => ["responsetime", "float"]
     }
     geoip {
       source => "clientip"
       target => "geoip"
       add_tag => ["nginx-geoip"]
     }
     date {
       match => ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]
       remove_field => ["timestamp"]
     }
     useragent {
       source => "agent"
     }
    }

    output {
     elasticsearch {
       hosts => ["localhost:9200"]
       index => "weblog"
       document_type => "my_type"
     }
     stdout { codec => rubydebug }
    }

```

I have tried creating a custom index using `PUT _template/weblog` and setting `"location" : {"type" : "geo_point"},`(along with all other field mappings) and receive a message stating:

```auto
    #! Deprecation: Deprecated field [template] used, replaced by [index_patterns]
            {
              "acknowledged" : true
            }

```

I then deleted the old index and when it is recreated though the receipt of NGINX logs from Logstash, I view the mapping, location is changed back to a float.

Any help appreciated. Thanks

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [June 20, 2020, 9:45am UTC](https://discuss.elastic.co/t/getting-geoip-field-for-nginx-logs/237903/2 "2020-06-20T09:45:22Z")

</div>

Create custom mapping for your needs

```auto
{
"geoip" : {
  "dynamic": true,
  "properties" : {
    "ip": { "type": "ip" },
    "location" : { "type" : "geo_point" },
    "latitude" : { "type" : "half_float" },
    "longitude" : { "type" : "half_float" }
 }
}

```

Put into output

```auto
output {
   elasticsearch {
     hosts => ["http://elastic01:9200"]
     template => "/file/path/geo-template.json"
     template_overwrite => true
     manage_template => true
   }
# stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2020, 9:49am UTC](https://discuss.elastic.co/t/getting-geoip-field-for-nginx-logs/237903/3 "2020-07-18T09:49:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
