# Kibana 4 and geoip

**URL:** <https://discuss.elastic.co/t/kibana-4-and-geoip/1665>\
**Category:** Kibana\
**Created:** [June 1, 2015, 9:26pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665 "2015-06-01T21:26:12Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [June 1, 2015, 9:26pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/1 "2015-06-01T21:26:12Z")

</div>

Hi Guys,  
I have created some indexes on ES, using LogStash, and then trying to visualise with Kibana 4.

To visualise the geo data I try to select a 'Tile Map' and then 'Aggregation' with Geohash, and finally 'Field' of geoip.location.

This fails with :

```
Error: Request to Elasticsearch failed: {"error":"SearchPhaseExecutionException[Failed to execute phase [query], all shards failed; shardFailures {[uyUOwArCTO2S1muPN1HAiw][logstash-2015.01][0]: ClassCastException[org.elasticsearch.index.fielddata.plain.DoubleArrayIndexFieldData cannot be cast to org.elasticsearch.index.fielddata.IndexGeoPointFieldData]}{[uyUOwArCTO2S1muPN1HAiw][logstash-2015.02][0]: 

```

Clearly something is wrong. Have I mucked up my index? I have set the geop field to be "not analyzed" and I have left the geop.location fields as is. Any clues what is wrong?

Here is a sample of the geoip.location field:

```
geoip.location ["4.900000000000006","52.36670000000001"]

```

And here is the mapping:

```
          "geoip": {
        "properties": {
          "timezone": {
            "type": "string"
          },
          "region_name": {
            "type": "string"
          },
          "real_region_name": {
            "type": "string"
          },
          "postal_code": {
            "type": "string"
          },
          "longitude": {
            "type": "double"
          },
          "location": {
            "type": "double"
          },
          "latitude": {
            "type": "double"
          },
          "area_code": {
            "type": "long"
          },
          "city_name": {
            "type": "string"
          },
          "continent_code": {
            "type": "string"
          },
          "country_code2": {
            "type": "string"
          },
          "country_code3": {
            "type": "string"
          },
          "country_name": {
            "type": "string"
          },
          "dma_code": {
            "type": "long"
          },
          "ip": {
            "type": "string"
          }
        }
      },
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2015, 11:19am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/2 "2015-06-02T11:19:29Z")

</div>

It needs to be `"type": "geo_point"` for `geoip.location`.

---

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [June 2, 2015, 4:00pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/3 "2015-06-02T16:00:41Z")

</div>

Thanks you Mark. I feared this was the case.

What is the quickest way of me correcting this? How do I change the type for a field? Do I have to index?? oh no! Or can I do that efficiently?

Update: Reading some posts and docs implies I might be able to do this by greating a new index with the correct mapping, and then doing a scrolled search to pull in the data from the old index?  
[https://www.elastic.co/blog/changing-mapping-with-zero-downtime](https://www.elastic.co/blog/changing-mapping-with-zero-downtime)

Can someone expand on the mechanics and practicality of doing this? I have 5 indexes and they each have about 80 million docs so the re-indexing is not trivial.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2015, 9:43pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/4 "2015-06-02T21:43:39Z")

</div>

Just use this to reindex with Logstash - [https://gist.github.com/markwalkom/8a7201e3f6ea4354ae06](https://gist.github.com/markwalkom/8a7201e3f6ea4354ae06)

---

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [June 2, 2015, 10:19pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/5 "2015-06-02T22:19:21Z")

</div>

Thanks again Mark. I will test it out.  
Could you outline what it is doing? Looks like it is doing the scrolled search and then outputing back to the new index?  
I presume I should delete and add a new corrected template before doing this, so that I have the correct mapping for the geoip.location field?  
Ta  
Paul

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2015, 11:06pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/6 "2015-06-02T23:06:17Z")

</div>

That's what it does, yes.

You will need to update the template, you will also need to reindex to a new index name, you can't just do it over the top of the existing one.

---

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [June 3, 2015, 6:52am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/7 "2015-06-03T06:52:05Z")

</div>

Where do I specify the name of the new index? The logstash conf example you used some metadata but do I set it in the {output} section in the usual way?  
eg;  
index =\> "new\_log-%{+YYYY.MM}"

Thanks

---

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [June 3, 2015, 10:30am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/8 "2015-06-03T10:30:43Z")

</div>

Ok, I have the re-index working. My new index has a lovely geoip.location field that is type: geo\_point.

```
              "location" : {
            "type" : "geo_point"
          },

```

And the actual data looks ok as well:

```
geoip.location [-73.627,4.142]

```

However when I go over to Kibana and try to visualise on a Tile Map I get an error. I select "geohash" for the aggregation (the only option) and there is no option available for "field". Any ideas? Why no geoip.location available?

---

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [June 3, 2015, 11:26am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/9 "2015-06-03T11:26:29Z")

</div>

Fixed it : Go to "Settings" on the main Kibana dashboard. Then delete the old index pattern and add the new index pattern. Check the geoip.location field is showing as "geo\_point".

Without this refresh, Kibana was using the old type field for geoip.location

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 3, 2015, 12:01pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/10 "2015-06-03T12:01:17Z")

</div>

Yep, you can do this by issuing a refresh under the settings for the index.

---

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [June 3, 2015, 12:38pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/11 "2015-06-03T12:38:06Z")

</div>

Thanks Mark. Its all working.

One last question (promise!): Performance

What is the best way to do this for an ES cluster of 4 nodes, with 4 indexes, each index 4 shards (one per node)?

Should I do one index all local (input & output same node) or input on node1 output to node2?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 3, 2015, 11:13pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/12 "2015-06-03T23:13:46Z")

</div>

One shard per node is good, don't forget replicas though! 😄  
However you are better off having an uneven number of nodes to ensure quorum.

You are also definitely better off spreading the indexing load across mutiple servers.

---

<div class="post-metadata">

**Author:** ![ctataryn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ctataryn/32/10805_2.png) [@ctataryn](https://discuss.elastic.co/u/ctataryn)\
**Post date:** [July 13, 2016, 9:45pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/13 "2016-07-13T21:45:21Z")

</div>

I've tried doing a refresh, but my geoip.location is still listed as of type `Number` and don't have the option to change it to "geo\_point" through the GUI.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1240a855ccf78f0d1822a67791da93026f7a2008.jpg)

As far as I know this was working a few days ago (I'm using the Cloud instance of Kibana). When I check my documents I do see proper data like so:

```
"geoip": {
  "ip": "XX.XX.XXX.XX",
  "location": [
    -111.8906,
    33.61189999999999
  ]
}

```

Is there something else I'm missing?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 13, 2016, 10:22pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/14 "2016-07-13T22:22:46Z")

</div>

Check the mapping of the field, that'll tell you definitively.

---

<div class="post-metadata">

**Author:** ![ctataryn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ctataryn/32/10805_2.png) [@ctataryn](https://discuss.elastic.co/u/ctataryn)\
**Post date:** [July 14, 2016, 12:52am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/15 "2016-07-14T00:52:27Z")

</div>

@warkolm Where do I find the _mapping_ of the field?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 14, 2016, 12:53am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/16 "2016-07-14T00:53:17Z")

</div>

Look at `GET /indexname/_mapping`

---

<div class="post-metadata">

**Author:** ![bob\_webman](https://avatars.discourse-cdn.com/v4/letter/b/6de8d8/32.png) [@bob\_webman](https://discuss.elastic.co/u/bob_webman)\
**Post date:** [July 14, 2016, 4:55am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/17 "2016-07-14T04:55:41Z")

</div>

Like @warkolm said, GET /indexname/\_mapping and here is what I get when I do that:  
[Note the location \<-\> geo\_point mapping]

```auto
          "geoip": {
            "properties": {
              "timezone": {
                "type": "string"
              },
              "region_name": {
                "type": "string"
              },
              "real_region_name": {
                "type": "string"
              },
              "postal_code": {
                "type": "string"
              },
              "longitude": {
                "type": "float"
              },
              "location": {
                "type": "geo_point"
              },
              "latitude": {
                "type": "float"
              },
              "ip": {
                "type": "string"
              },
              "area_code": {
                "type": "string"
              },
              "city_name": {
                "type": "string"
              },
              "continent_code": {
                "type": "string"
              },
              "coordinates": {
                "type": "double"
              },
              "country_code2": {
                "type": "string"
              },
              "country_code3": {
                "type": "string"
              },
              "country_name": {
                "type": "string"
              },
              "dma_code": {
                "type": "string"
              }
            },

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2016, 6:04am UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/18 "2016-07-14T06:04:14Z")

</div>

Perhaps you just need to refresh the field list in Kibana?

---

<div class="post-metadata">

**Author:** ![ctataryn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ctataryn/32/10805_2.png) [@ctataryn](https://discuss.elastic.co/u/ctataryn)\
**Post date:** [July 14, 2016, 3:20pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/19 "2016-07-14T15:20:06Z")

</div>

Where as mine is:

> ```
> "geoip": {
> "properties": {
> "area_code": {
> "type": "long"
> },
> "city_name": {
> "type": "string"
> },
> "continent_code": {
> "type": "string"
> },
> "country_code2": {
> "type": "string"
> },
> "country_code3": {
> "type": "string"
> },
> "country_name": {
> "type": "string"
> },
> "dma_code": {
> "type": "long"
> },
> "ip": {
> "type": "string"
> },
> "latitude": {
> "type": "double"
> },
> "location": {
> "type": "double"
> },
> "longitude": {
> "type": "double"
> },
> "postal_code": {
> "type": "string"
> },
> "real_region_name": {
> "type": "string"
> },
> "region_name": {
> "type": "string"
> },
> "timezone": {
> "type": "string"
> }
> }
> },
> 
> ```

When I went to change the type (see previous post) it didn't give me the option to choose `geo_point`.

Craig.

---

<div class="post-metadata">

**Author:** ![ctataryn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ctataryn/32/10805_2.png) [@ctataryn](https://discuss.elastic.co/u/ctataryn)\
**Post date:** [July 14, 2016, 3:22pm UTC](https://discuss.elastic.co/t/kibana-4-and-geoip/1665/20 "2016-07-14T15:22:20Z")

</div>

I have tried that but it doesn't seem to help. I go into Kibana, click on `Settings` then I click on the index pattern and finally click the yellow `Refresh` icon.

Craig.

[Next page](https://discuss.elastic.co/t/kibana-4-and-geoip/1665.md?page=2)
