# Kibana how to get geo\_point working?

**URL:** <https://discuss.elastic.co/t/kibana-how-to-get-geo-point-working/54579>\
**Category:** Kibana\
**Created:** [July 2, 2016, 12:48pm UTC](https://discuss.elastic.co/t/kibana-how-to-get-geo-point-working/54579 "2016-07-02T12:48:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tommo](https://avatars.discourse-cdn.com/v4/letter/t/ebca7d/32.png) [@Tommo](https://discuss.elastic.co/u/Tommo)\
**Post date:** [July 2, 2016, 12:48pm UTC](https://discuss.elastic.co/t/kibana-how-to-get-geo-point-working/54579/1 "2016-07-02T12:48:09Z")

</div>

For the life of me I can't get geo-ip working any help would be greatly accepted.  
Here is the error in Kibana:  
"No Compatible Fields: The "syslog-\*" index pattern does not contain any of the following field types: geo\_point"

Question is how do I fix it?

in my filter I have the following:  
geoip {  
database =\> "/etc/logstash/GeoLiteCity.dat"  
source =\> "src\_IP"  
target =\> "geoip"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}

I get the following out put:

```
"geoip": {
  "ip": "85.25.235.85",
  "country_code2": "DE",
  "country_code3": "DEU",
  "country_name": "Germany",
  "continent_code": "EU",
  "latitude": 51,
  "longitude": 9,
  "timezone": "Europe/Berlin",
  "location": [
    9,
    51
  ],
  "coordinates": [
    9,
    51
  ]
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 3, 2016, 10:51pm UTC](https://discuss.elastic.co/t/kibana-how-to-get-geo-point-working/54579/2 "2016-07-03T22:51:04Z")

</div>

What are those fields mapped as in ES?  
Check with the `_mapping` endpoint?

---

<div class="post-metadata">

**Author:** ![Tommo](https://avatars.discourse-cdn.com/v4/letter/t/ebca7d/32.png) [@Tommo](https://discuss.elastic.co/u/Tommo)\
**Post date:** [July 4, 2016, 12:14am UTC](https://discuss.elastic.co/t/kibana-how-to-get-geo-point-working/54579/3 "2016-07-04T00:14:24Z")

</div>

Thanks Mark,  
I don't see any types that = "geo\_point" so I assume I must set this but from that I assume I must also change the template so that it is set on a permanent basis?

Is there a curl "put" to modify the existing indices and where would I then change template?

Here is the output from the \_mapping:

{"syslog-2016.07.04":{"mappings":{"syslog":{"properties":{"@timestamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"@version":{"type":"string"},"dest\_IP":{"type":"string"},"dst\_addr":{"type":"string"},"dst\_port":{"type":"string"},"from\_zone":{"type":"string"},"geoip":{"properties":{"area\_code":{"type":"long"},"city\_name":{"type":"string"},"continent\_code":{"type":"string"},"coordinates":{"type":"double"},"country\_code2":{"type":"string"},"country\_code3":{"type":"string"},"country\_name":{"type":"string"},"dma\_code":{"type":"long"},"ip":{"type":"string"},"latitude":{"type":"double"},"location":{"type":"double"},"longitude":{"type":"double"},"postal\_code":{"type":"string"},"real\_region\_name":{"type":"string"},"region\_name":{"type":"string"},"timezone":{"type":"string"}}},"host":{"type":"string"},"message":{"type":"string"},"policy\_name":{"type":"string"},"protocol\_id":{"type":"string"},"received\_at":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"received\_from":{"type":"string"},"service":{"type":"string"},"src\_IP":{"type":"string"},"src\_addr":{"type":"string"},"src\_port":{"type":"string"},"syslog\_hostname":{"type":"string"},"syslog\_message":{"type":"string"},"syslog\_pid":{"type":"string"},"syslog\_pri":{"type":"string"},"syslog\_program":{"type":"string"},"syslog\_timestamp":{"type":"string"},"to\_zone":{"type":"string"},"type":{"type":"string"}}}}}}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 4, 2016, 2:57am UTC](https://discuss.elastic.co/t/kibana-how-to-get-geo-point-working/54579/4 "2016-07-04T02:57:53Z")

</div>

Ok, so you need to add that to the template/mapping for the field. You don't need the `location` and `coordinates` fields though, just pick one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/kibana-how-to-get-geo-point-working/54579/5 "2017-07-06T13:48:26Z")

</div>


