# How to change two fields in an index to a geo point?

**URL:** <https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033>\
**Category:** Logstash\
**Created:** [October 14, 2020, 11:33am UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033 "2020-10-14T11:33:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![witcher](https://avatars.discourse-cdn.com/v4/letter/w/91b2a8/32.png) [@witcher](https://discuss.elastic.co/u/witcher)\
**Post date:** [October 14, 2020, 11:33am UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033/1 "2020-10-14T11:33:00Z")

</div>

```
PUT _ingest/pipeline/geoip    
{
"description" : "Add geoip info",
"processors" : [
 {
  "geoip" : {
    "field" : "source_ip",
    "database_file": "GeoLite2-City.mmdb",
    "target_field": "sourceip_geo"
  }
}
]
}    

```

then I run this and refresh the index

```
POST ips/_update_by_query?pipeline=geoip

```

my log in the discovery tab looks like this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/106f0e186129fb500dd87ad70fd727643dc1d31e.png)

what i want to do is convert the latitude and longitude in a geo point format so I can plot.

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [October 14, 2020, 1:25pm UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033/2 "2020-10-14T13:25:25Z")

</div>

You have to update first your ips index mapping and map field sourceip\_geo.location into a geo\_point type

---

<div class="post-metadata">

**Author:** ![witcher](https://avatars.discourse-cdn.com/v4/letter/w/91b2a8/32.png) [@witcher](https://discuss.elastic.co/u/witcher)\
**Post date:** [October 14, 2020, 2:48pm UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033/4 "2020-10-14T14:48:00Z")

</div>

> [@ylasri](#):
>
> You have to update first your ips index mapping and map field sourceip\_geo.location into a geo\_point type

@ylasri i guess I am not following you

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [October 14, 2020, 2:49pm UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033/5 "2020-10-14T14:49:37Z")

</div>

Share your index mapping, use this from dev Console

`GET ips/_mapping`

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [October 14, 2020, 3:10pm UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033/8 "2020-10-14T15:10:41Z")

</div>

I suppose that you have imported data using ML importer, you source file contain only 2 fields :

- source\_ip
- dest\_ip

The initial mapping will be

```
PUT ips
{
  "settings": {
    "number_of_shards": 1,
    "number_of_replicas": 0
  },
  "mappings": {
    "_meta": {
      "created_by": "ml-file-data-visualizer"
    },
    "properties": {
      "dest_ip": {
        "type": "ip"
      },
      "source_ip": {
        "type": "ip"
      }
    }
  }
}

```

Now before you update your index with the ingest pipeline, you should first update the index mapping as follow

```
PUT ips/_mapping
{
  "properties": {
    "sourceip_geo": {
      "properties": {
        "city_name": {
          "type": "keyword"
        },
        "continent_name": {
          "type": "keyword"
        },
        "country_iso_code": {
          "type": "keyword"
        },
        "location": {
          "type": "geo_point"
        },
        "region_iso_code": {
          "type": "keyword"
        },
        "region_name": {
          "type": "keyword"
        }
      }
    }
  }
}

```

This is beacause you ingest pipeline is adding an object sourceip\_geo

```
PUT _ingest/pipeline/geoip
{
  "description": "Add geoip info",
  "processors": [
    {
      "geoip": {
        "field": "source_ip",
        "database_file": "GeoLite2-City.mmdb",
        "target_field": "sourceip_geo"
      }
    }
  ]
}
```

---

<div class="post-metadata">

**Author:** ![witcher](https://avatars.discourse-cdn.com/v4/letter/w/91b2a8/32.png) [@witcher](https://discuss.elastic.co/u/witcher)\
**Post date:** [October 14, 2020, 3:19pm UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033/9 "2020-10-14T15:19:47Z")

</div>

> [@ylasri](#):
>
> I suppose that you have imported data using ML importer, you source file contain only 2 fields :
> 
> - source\_ip
> - dest\_ip

@ylasri you are absolutely correct about the two fields and importer part  
okay I did as you said now the mapping is like this

```
{
"ips" : {
"mappings" : {
  "_meta" : {
    "created_by" : "ml-file-data-visualizer"
  },
  "properties" : {
    "dest_ip" : {
      "type" : "ip"
    },
    "source_ip" : {
      "type" : "ip"
    },
    "sourceip_geo" : {
      "properties" : {
        "city_name" : {
          "type" : "keyword"
        },
        "continent_name" : {
          "type" : "keyword"
        },
        "country_iso_code" : {
          "type" : "keyword"
        },
        "location" : {
          "type" : "geo_point"
        },
        "region_iso_code" : {
          "type" : "keyword"
        },
        "region_name" : {
          "type" : "keyword"
        }
      }
    }
  }
}
}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2020, 3:20pm UTC](https://discuss.elastic.co/t/how-to-change-two-fields-in-an-index-to-a-geo-point/252033/10 "2020-11-11T15:20:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
