# Getting Kibana's geo hash with geo\_point type to work

**URL:** <https://discuss.elastic.co/t/getting-kibanas-geo-hash-with-geo-point-type-to-work/41243>\
**Category:** Kibana\
**Created:** [February 9, 2016, 7:07am UTC](https://discuss.elastic.co/t/getting-kibanas-geo-hash-with-geo-point-type-to-work/41243 "2016-02-09T07:07:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shat/32/3650_2.png) [@shat](https://discuss.elastic.co/u/shat)\
**Post date:** [February 9, 2016, 7:07am UTC](https://discuss.elastic.co/t/getting-kibanas-geo-hash-with-geo-point-type-to-work/41243/1 "2016-02-09T07:07:27Z")

</div>

I posted an issue on Github, forgetting all about the discussion forums here.

[issue outlined on github](https://github.com/elastic/kibana/issues/6159)

logstash 2.2.0  
kibana 4.4.0  
elasticsearch 2.2.x

#copy / paste from github#

I have the following mapping applied to an index, pulled via \_mapping API endpoint:

"cse-2016.02.09" : {  
"mappings" : {  
"event" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "strict\_date\_optional\_time||epoch\_millis"  
},  
"host" : {  
"type" : "string"  
},  
"src\_ip" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"src\_ip\_geo" : {  
"type" : "nested",  
"properties" : {  
"area\_code" : {  
"type" : "long"  
},  
"city\_name" : {  
"type" : "string"  
},  
"continent\_code" : {  
"type" : "string"  
},  
"coordinates" : {  
"type" : "geo\_point"  
},  
"country\_code2" : {  
"type" : "string"  
},  
"country\_code3" : {  
"type" : "string"  
},  
"country\_name" : {  
"type" : "string"  
},  
"dma\_code" : {  
"type" : "long"  
},  
"ip" : {  
"type" : "string"  
},  
"latitude" : {  
"type" : "double"  
},  
"location" : {  
"type" : "geo\_point"  
},  
"longitude" : {  
"type" : "double"  
},  
"postal\_code" : {  
"type" : "string"  
},  
"real\_region\_name" : {  
"type" : "string"  
},  
"region\_name" : {  
"type" : "string"  
},  
"timezone" : {  
"type" : "string"  
}  
}  
},  
"src\_ip\_network" : {  
"properties" : {  
"asn" : {  
"type" : "string"  
},  
"number" : {  
"type" : "string"  
}  
}  
},  
"src\_latitude" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"src\_longitude" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
}  
},  
"_default_" : { }  
}  
}  
My config for the index is:

input {  
file {  
path =\> "/var/log/community/events.log"  
start\_position =\> "end"  
}  
}

filter {  
json {  
source =\> "message"  
}

geoip {  
source =\> "src\_ip"  
target =\> "src\_ip\_geo"  
database =\> "/opt/GeoLiteCity.dat"  
add\_field =\> ["[src\_ip\_geo][coordinates]", "%{[src\_ip\_geo][longitude]}" ]  
add\_field =\> ["[src\_ip\_geo][coordinates]", "%{[src\_ip\_geo][latitude]}" ]  
}  
mutate {  
convert =\> ["[src\_ip\_geo][coordinates]", "float"]  
}

geoip {  
source =\> "dst\_ip"  
target =\> "dst\_ip\_geo"  
database =\> "/opt/GeoLiteCity.dat"  
add\_field =\> ["[dst\_ip\_geo][coordinates]", "%{[dst\_ip\_geo][longitude]}" ]  
add\_field =\> ["[dst\_ip\_geo][coordinates]", "%{[dst\_ip\_geo][latitude]}" ]  
}

mutate {  
convert =\> ["[dst\_ip\_geo][coordinates]", "float"]  
}

geoip {  
source =\> "src\_ip"  
target =\> "src\_ip\_network"  
database =\> "/opt/GeoIPASNum.dat"  
}  
}

output {  
elasticsearch {  
hosts =\> ["10.0.100.36:9200"]  
index =\> "cse-%{+YYYY.MM.dd}"  
document\_type =\> "event"  
template\_name =\> "community\_sensor\_event"  
template =\> "/etc/logstash/cse-template.json"  
template\_overwrite =\> true  
manage\_template =\> true  
}  
}  
my mappings template consists of the fields from \_mappings api for the relevant fields I am trying to put on the kibana tile map are:

"src\_ip\_geo": {  
"type": "nested",  
"properties": {  
"coordinates": {  
"type": "geo\_point"  
},  
"location": {  
"type": "geo\_point"  
}  
}  
},  
I have not been able to dig out why kibana is erroring, any ideas?

`  
pulling the JSON from the log lines, shows:

```
"src_ip_geo": {
  "ip": "203.xxx.xxx.xxx",
  "country_code2": "LK",
  "country_code3": "LKA",
  "country_name": "Sri Lanka",
  "continent_code": "AS",
  "latitude": 7,
  "longitude": 81,
  "timezone": "Asia/Colombo",
  "location": [
    81,
    7
  ],
  "coordinates": [
    81,
    7
  ]
},

```

`

I have not found anything useful in any Kibana logs, so I am not sure how to proceed.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 10, 2016, 2:09am UTC](https://discuss.elastic.co/t/getting-kibanas-geo-hash-with-geo-point-type-to-work/41243/2 "2016-02-10T02:09:25Z")

</div>

You have `src_ip_geo` mapped as;

```auto
"src_ip_geo" : {
"type" : "nested",
"properties" : {
"area_code" : {
"type" : "long"
},

```

Which is not a geo point.

---

<div class="post-metadata">

**Author:** ![shat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shat/32/3650_2.png) [@shat](https://discuss.elastic.co/u/shat)\
**Post date:** [February 10, 2016, 2:50am UTC](https://discuss.elastic.co/t/getting-kibanas-geo-hash-with-geo-point-type-to-work/41243/3 "2016-02-10T02:50:26Z")

</div>

Mark,

I have the type on src\_ip\_geo set to "nested" because it has additional fields below it. I could be very wrong in my understanding of how this should be done, but that is what I was able to gather from reading the documentation as well as a bit of testing. I have the specific fields I want to be geo\_points specified within that object:

```auto
 "properties": {
        "src_ip_geo": {
          "type": "nested",
          "properties": {
            "coordinates": {
              "type": "geo_point"
            },
            "location": {
              "type": "geo_point"
            }
          }
        },

```

Does the nested replace what I am attempting to do? Going to reach out on twitter/IRC and I'll update this thread with any progress.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 10, 2016, 5:32am UTC](https://discuss.elastic.co/t/getting-kibanas-geo-hash-with-geo-point-type-to-work/41243/4 "2016-02-10T05:32:39Z")

</div>

That looks fine then.

KB sees the field as a geopoint?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:02pm UTC](https://discuss.elastic.co/t/getting-kibanas-geo-hash-with-geo-point-type-to-work/41243/5 "2017-07-06T14:02:41Z")

</div>


