Hello,
I have parsed the an auth.log via grok and elasticsearch is looking up the IP geo location but the system.auth.ssh.geoip.city_name field is set as string and not geopoint. Is it possible to change it's type somehow?
Regards,
Peter
Hello,
I have parsed the an auth.log via grok and elasticsearch is looking up the IP geo location but the system.auth.ssh.geoip.city_name field is set as string and not geopoint. Is it possible to change it's type somehow?
Regards,
Peter
This is better answered in your other thread - Geo_point is not getting mapped correctly
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.