# How to define dynamic templates for geo\_point in a custom Integration (Fleet + elastic-package)?

**URL:** <https://discuss.elastic.co/t/how-to-define-dynamic-templates-for-geo-point-in-a-custom-integration-fleet-elastic-package/382524>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [October 8, 2025, 2:01pm UTC](https://discuss.elastic.co/t/how-to-define-dynamic-templates-for-geo-point-in-a-custom-integration-fleet-elastic-package/382524 "2025-10-08T14:01:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![B\_Grimm](https://avatars.discourse-cdn.com/v4/letter/b/f17d59/32.png) [@B\_Grimm](https://discuss.elastic.co/u/B_Grimm)\
**Post date:** [October 8, 2025, 2:01pm UTC](https://discuss.elastic.co/t/how-to-define-dynamic-templates-for-geo-point-in-a-custom-integration-fleet-elastic-package/382524/1 "2025-10-08T14:01:49Z")

</div>

# How to define dynamic templates for `geo_point` in a custom Integration (Fleet + elastic-package)?

**Context**

I’m building a custom **Elastic Integration** with `elastic-package` (Fleet-managed data streams).  
Some events contain coordinates under deeply nested fields like:

```auto
Message.Detail.LocationContent.LogicalLocation.Coordinates.GeographicPosition

```

Values arrive as strings in `"lat, lon"` format, e.g. `47.44185, 9.418687`.

**Goal**

Automatically map **any field whose name ends with `GeographicPosition`** to **`geo_point`** , without having to enumerate full paths. This is to enable Kibana Maps, geo filters, and distance queries out of the box.

* * *

## What already works (manually in Kibana)

If I create a **dynamic template** manually in Kibana (Index Template → Mappings), Elasticsearch accepts it and it works exactly as desired:

```json
"dynamic_templates": [
  {
    "template_name": {
      "match": "*GeographicPosition",
      "match_mapping_type": "*",
      "mapping": {
        "type": "geo_point"
      }
    }
  }
]

```

So the capability exists on the Elasticsearch side. The open question is how to express this within a Fleet-managed Integration package so it passes validation and installs cleanly via elastic-package install.

## What I already tried in `fields.yml` (failed)

**Example 1 (installs, but wrong type):**

```yaml
- name: '*GeographicPosition'
  type: text
  description: Dynamic mapping for all GeographicPosition values

```

This builds and installs, but of course maps the fields as `text`, not `geo_point`.

**Example 2 (fails at install time):**

```yaml
- name: '*GeographicPosition'
  type: geo_point
  description: Dynamic mapping for all GeographicPosition values

```

Build works, but **install fails** with:

```auto
No dynamic mapping generated for field *GeographicPosition of type geo_point

```

(Using `*.GeographicPosition` shows the same behavior. I also verified that `path_match: "*.GeographicPosition"` is **not allowed** in `fields.yml` per the package linter.)

## Ask: What are the supported procedures to create **dynamic `geo_point` templates** inside an Integration?

I’m looking for the **official / recommended** ways to achieve a wildcarded `geo_point` mapping in a package:

- How should a package author **define dynamic templates** for `geo_point` when using **Fleet-managed data streams**?
  - Is it supported via `fields.yml` (and if so, what’s the correct syntax for a wildcard like `*GeographicPosition` to become a `geo_point`)?
  - If not via `fields.yml`, should this be done via the data stream’s `manifest.yml` as part of `elasticsearch.index_template.mappings`?
  - Or should we create a **component template** at the package level and reference it from the data stream’s index template (`composed_of`)?

- Are there **known limitations** on generating `geo_point` dynamic templates from the Integration packaging model (e.g., certain types allowed via `fields.yml` vs. those that must be expressed in an index/component template)?
- For wildcard matching:
  - Is `match: "*GeographicPosition"` the right approach?
  - Are there cases where `path_match` is required/allowed in this context?
  - Any guidance on `match_mapping_type` (e.g., `"*"` vs. `"string"`), given that values arrive as `"lat, lon"` strings?

- Are there **example packages** (official or community) that showcase a working dynamic template for `geo_point` with wildcards in a Fleet Integration?

## Environment

- Elastic Agent / Fleet: **9.1.x** (Windows hosts)
- Integration built with **`elastic-package`**
- Data stream type: **`logs`**
- Example value: `"47.44185, 9.418687"` (string)

Any pointers to documentation, a minimal example, or best practices for packaging `geo_point` **dynamic templates** inside a Fleet Integration would be greatly appreciated. Thanks!

---

<div class="post-metadata">

**Author:** ![B\_Grimm](https://avatars.discourse-cdn.com/v4/letter/b/f17d59/32.png) [@B\_Grimm](https://discuss.elastic.co/u/B_Grimm)\
**Post date:** [October 29, 2025, 3:45pm UTC](https://discuss.elastic.co/t/how-to-define-dynamic-templates-for-geo-point-in-a-custom-integration-fleet-elastic-package/382524/2 "2025-10-29T15:45:20Z")

</div>

Does anyone perhaps have an answer to this question?

Tanks

---

<div class="post-metadata">

**Author:** ![Thomas\_Huber](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_huber/32/139739_2.png) [@Thomas\_Huber](https://discuss.elastic.co/u/Thomas_Huber)\
**Post date:** [November 11, 2025, 12:39pm UTC](https://discuss.elastic.co/t/how-to-define-dynamic-templates-for-geo-point-in-a-custom-integration-fleet-elastic-package/382524/3 "2025-11-11T12:39:40Z")

</div>

Anyone? We face the same problem and would appreciate a solution…
