# Is there any way to find the "xxx" that produces the most geo data？

**URL:** https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142
**Category:** Kibana
**Created:** [July 30, 2020, 1:23am UTC](https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142 "2020-07-30T01:23:06Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)
#### Post date: [July 30, 2020, 1:23am UTC](https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142/1 "2020-07-30T01:23:07Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/3/138771b5f2a13dbbbfeb59607525506dc76b668c.png)

I did not find the visitor information for this location in Zhengzhou in the city list.

I want to find out the "XX" serivce traffic information corresponding to geo\_localtion.

> serive.name geo\_localtion  
> xxxx 113.11111,22.1111

The data source is kubernetes ingress.

mapping  
[https://paste.ubuntu.com/p/qWqGNrggbf/](https://paste.ubuntu.com/p/qWqGNrggbf/)

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 30, 2020, 1:38am UTC](https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142/2 "2020-07-30T01:38:18Z")

</div>

That's definitely possible, have you tried an aggregation on the `geoip.location` field?

---

<div class="post-metadata">

### Author: ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)
#### Post date: [July 30, 2020, 6:11am UTC](https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142/3 "2020-07-30T06:11:59Z")

</div>

The geoip.location field cannot be used as an aggregation condition.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/4/247f4187432a51ccace575a01710941e8e1c3d5f.png)

I tried several methods, but the amount of data displayed is very different from the amount on the map.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/4/24396b9c16e77ecca404295452f845ac15b209b9.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/d/ddc93fa1642825f673e427c6cf082bac8355e179.png)

---

<div class="post-metadata">

### Author: ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)
#### Post date: [July 30, 2020, 3:01pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142/4 "2020-07-30T15:01:46Z")

</div>

@wajika

Thanks for posting your question. Can you describe your use case more? What are you looking for in the table on the right of the map? Could this problem be better solved with drilldowns, allowing you to link into a dashboard with the context of a specific IP address? Are you just looking for the latest documents for this IP address? Would showing raw documents help?

---

<div class="post-metadata">

### Author: ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)
#### Post date: [July 31, 2020, 1:48am UTC](https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142/5 "2020-07-31T01:48:13Z")

</div>

@Nathan_Reese  
Sorry, I did not express it clearly.  
The problem I encountered was that I found that my visitor information (geo) was incorrectly displayed on the map, and the largest mark on the map did not match the actual location of my customer. I want to find out the reason, but the geo\_localtion field cannot be queried as an aggregation condition.  
I want to know if the elastic team has a better way to pinpoint this anomaly.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 28, 2020, 1:48am UTC](https://discuss.elastic.co/t/is-there-any-way-to-find-the-xxx-that-produces-the-most-geo-data/243142/6 "2020-08-28T01:48:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
