# Location Mapping

**URL:** <https://discuss.elastic.co/t/location-mapping/193615>\
**Category:** Logstash\
**Created:** [August 2, 2019, 7:34pm UTC](https://discuss.elastic.co/t/location-mapping/193615 "2019-08-02T19:34:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 2, 2019, 7:34pm UTC](https://discuss.elastic.co/t/location-mapping/193615/1 "2019-08-02T19:34:31Z")

</div>

I want solution for location mapping for my dataset. Following is the link for my dataset:

> **[Crimes in Boston](https://www.kaggle.com/AnalyzeBoston/crimes-in-boston)**
>
> Times, locations, and descriptions of crimes

I am not able to get location type geo\_point for mapping. Kindly advise.

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [August 2, 2019, 8:18pm UTC](https://discuss.elastic.co/t/location-mapping/193615/2 "2019-08-02T20:18:45Z")

</div>

Hi @aaditya_alekar,

It looks like that data set you linked to includes `location` data with a `lat` and `long`, so you should be able to ingest that as a `geo_point` fairly easily. There are [several different formats](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html) that will work with Elasticsearch (object, string, geohash, array).

You'll need to use logstash or [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/master/pipeline.html) to make sure the `lat` and `long` are changed to the `geo_point` shape at ingest time. See this thread for an example of how that works: [Problem converting latitude and longitude into a geo point for Kibana](https://discuss.elastic.co/t/problem-converting-latitude-and-longitude-into-a-geo-point-for-kibana/52856/12)

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 2, 2019, 9:30pm UTC](https://discuss.elastic.co/t/location-mapping/193615/3 "2019-08-02T21:30:52Z")

</div>

I am not able to create logstash config file using mac terminal. Kindly advise

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [August 2, 2019, 10:09pm UTC](https://discuss.elastic.co/t/location-mapping/193615/4 "2019-08-02T22:09:57Z")

</div>

You may want to start with the [configuring logstash](https://www.elastic.co/guide/en/logstash/current/configuration.html) docs to get an idea as to how this process looks. It involves creating a `.conf` file, which you can do from the command line.

Also for your case, perhaps this thread, though old, would be even more useful: [How to process "Lat" & "Long" fields using default Logstash config and mapping to use in Kibana 4 tile map](https://discuss.elastic.co/t/how-to-process-lat-long-fields-using-default-logstash-config-and-mapping-to-use-in-kibana-4-tile-map/23398/8)

It includes a link to [this blog post](http://david.pilato.fr/blog/2015/04/28/exploring-capitaine-train-dataset/) which gives some concrete examples of using `mutate` to turn separate `latitude` and `longitude` values into a geo\_point `location`.

(I'm going to re-categorize this discussion under Logstash since it's more relevant to ingesting data... hope that's okay!) 🙂

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 3, 2019, 12:15am UTC](https://discuss.elastic.co/t/location-mapping/193615/5 "2019-08-03T00:15:18Z")

</div>

input{  
file{  
path =\> " /Users/aadi2391/Desktop/Documents/CIS5900\ Project/311\_Service\_Requests\_from\_2010\_to\_Present.csv "  
start position =\> "beginning"  
"sincedb\_path" =\> "/dev/null"  
}  
}

filter {  
csv {  
seperator =\> ","  
columns =\> { }  
}

```
      date {
           locale => "eng"
           match => {"Created Date" , "MM/dd/yyyy HH:mm:ss aa" , "ISO8601"
           target => "Date"
           remove_field => ["Created Date"]
           }
    mutate { convert => {"Latitude" => "float"} }
    mutate { convert => {"Longitude" => "float"} }
    mutate { rename => {"Latitude" => "[location][lat]"} }
    mutate { rename => {"Longitude" => "[location][lon]"} }
    
    }

```

output{

elasticsearch {  
Hosts =\> ["localhost:9200"]  
index =\> "nyc311calls"  
document\_type =\> "calls"  
user =\> "elastic"  
password =\> "changeme"}  
stdout { codec =\> rubydebug { metadata =\> true } }  
stdout { codec =\> dots }  
}  
is this correct?

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 3, 2019, 1:47am UTC](https://discuss.elastic.co/t/location-mapping/193615/6 "2019-08-03T01:47:15Z")

</div>

can someone please help?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 3, 2019, 2:47am UTC](https://discuss.elastic.co/t/location-mapping/193615/7 "2019-08-03T02:47:11Z")

</div>

Hi you need to put a mapping in first if you have not done that ....

Example

```
PUT nyc311calls
{
  "mappings": {
    "properties": {
      "location": {
        "type": "geo_point"
      }
    }
  }
}

```

You need to do that before you run logstash and ingest documents otherwise you will not end up with a `geo_point` data type in the indexed documents

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 3, 2019, 2:54am UTC](https://discuss.elastic.co/t/location-mapping/193615/8 "2019-08-03T02:54:12Z")

</div>

Also my question was how can do a logstash config in mac?

Whats the command for that?

Also with my dataset which all possible visualization i could do? and how to find out the CPU usage?

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 3, 2019, 2:55am UTC](https://discuss.elastic.co/t/location-mapping/193615/9 "2019-08-03T02:55:18Z")

</div>

In the above mapping that you have provided what Index name should i give?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 3, 2019, 3:03am UTC](https://discuss.elastic.co/t/location-mapping/193615/10 "2019-08-03T03:03:38Z")

</div>

> [@aaditya\_alekar](#):
>
> In the above mapping that you have provided what Index name should i give?

When you create the mapping it should have the same name as the index you create.

Perhaps you should read the docs on mapping

> **[Mapping | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)**

@aaditya_alekar you are asking many different types of questions... It seems that perhaps you should work one step at a time.... And reference the excellent documents.

> [@aaditya\_alekar](#):
>
> Also my question was how can do a logstash config in mac?
> 
> Whats the command for that?

Please see

> **[Running Logstash from the Command Line | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html)**

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 4, 2019, 4:32pm UTC](https://discuss.elastic.co/t/location-mapping/193615/11 "2019-08-04T16:32:35Z")

</div>

bin/logstash -f /Users/aadi2391/Desktop/Documents/logstash-7.2.0/bin/logstash-Boston\_Crimes.conf

-bash: bin/logstash: No such file or directory

I am not able to run .conf using logstash? Kindly help

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 4, 2019, 4:48pm UTC](https://discuss.elastic.co/t/location-mapping/193615/12 "2019-08-04T16:48:41Z")

</div>

It does not have to do with the .conf file ... bash cannot find logstash.

- You need to run that command from the home directory where you installed logstash
- or use the full path to the logstash executable
- or add the path to the logstash executable to your path.

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 4, 2019, 5:10pm UTC](https://discuss.elastic.co/t/location-mapping/193615/13 "2019-08-04T17:10:10Z")

</div>

sir can you give an example?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 4, 2019, 5:16pm UTC](https://discuss.elastic.co/t/location-mapping/193615/14 "2019-08-04T17:16:31Z")

</div>

How did you install logstash on the Mac? Logstash does not come native on the Mac you need to install it.

Installation Instructions  
[https://www.elastic.co/guide/en/logstash/current/installing-logstash.html](https://www.elastic.co/guide/en/logstash/current/installing-logstash.html)

Downloads  
[https://www.elastic.co/downloads/logstash](https://www.elastic.co/downloads/logstash)

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 4, 2019, 6:04pm UTC](https://discuss.elastic.co/t/location-mapping/193615/15 "2019-08-04T18:04:48Z")

</div>

I installed logstash from the [elastic.co](http://elastic.co) by first downloading then unzipping it

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 4, 2019, 6:32pm UTC](https://discuss.elastic.co/t/location-mapping/193615/16 "2019-08-04T18:32:18Z")

</div>

Aadityas-MacBook:~ aadi2391$ logstash  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to /usr/local/Cellar/logstash-full/7.3.0/libexec/logs which is now configured via log4j2.properties  
ERROR: Pipelines YAML file is empty. Location: /usr/local/Cellar/logstash-full/7.3.0/libexec/config/pipelines.yml  
usage:  
bin/logstash -f CONFIG\_PATH [-t] [-r] [-w COUNT] [-l LOG]  
bin/logstash --modules MODULE\_NAME [-M "MODULE\_NAME.var.PLUGIN\_TYPE.PLUGIN\_NAME.VARIABLE\_NAME=VALUE"] [-t] [-w COUNT] [-l LOG]  
bin/logstash -e CONFIG\_STR [-t] [--log.level fatal|error|warn|info|debug|trace] [-w COUNT] [-l LOG]  
bin/logstash -i SHELL [--log.level fatal|error|warn|info|debug|trace]  
bin/logstash -V [--log.level fatal|error|warn|info|debug|trace]  
bin/logstash --help  
[2019-08-04T11:24:31,016][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

i tried to run logstash but it didnt work

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 4, 2019, 7:21pm UTC](https://discuss.elastic.co/t/location-mapping/193615/17 "2019-08-04T19:21:57Z")

</div>

Looks like you installed with brew as well I can see that by the error message.

You may have 2 logstash installed one from brew and one you downloaded. I think that's where your confusion is. I would remove one or the other.

So to run the brew version which is already in your path.

`logstash -f /Users/aadi2391/Desktop/Documents/logstash-7.2.0/bin/logstash-Boston_Crimes.conf`

Please show the exact command you are running.

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 4, 2019, 7:31pm UTC](https://discuss.elastic.co/t/location-mapping/193615/18 "2019-08-04T19:31:35Z")

</div>

Aadityas-MacBook:documents aadi2391$ logstash -f /Users/aadi2391/Desktop/Documents/logstash-7.2.0/bin/logstash-Boston\_Crimes.conf  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to /usr/local/Cellar/logstash-full/7.3.0/libexec/logs which is now configured via log4j2.properties  
[2019-08-04T12:30:01,387][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-08-04T12:30:01,417][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.3.0"}  
[2019-08-04T12:30:02,696][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, =\> at line 4, column 12 (byte 111) after input{\n file{\n path =\> " /Users/aadi2391/Desktop/Documents/CIS5900\ Project/crime\ 2.csv "\n start ", :backtrace=\>["/usr/local/Cellar/logstash-full/7.3.0/libexec/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/local/Cellar/logstash-full/7.3.0/libexec/logstash-core/lib/logstash/compiler.rb:49:in`compile\_graph'", "/usr/local/Cellar/logstash-full/7.3.0/libexec/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in`map'", "/usr/local/Cellar/logstash-full/7.3.0/libexec/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:151:in`initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/local/Cellar/logstash-full/7.3.0/libexec/logstash-core/lib/logstash/java_pipeline.rb:24:in`initialize'", "/usr/local/Cellar/logstash-full/7.3.0/libexec/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/local/Cellar/logstash-full/7.3.0/libexec/logstash-core/lib/logstash/agent.rb:325:in`block in converge\_state'"]}  
[2019-08-04T12:30:03,220][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-08-04T12:30:08,215][INFO][logstash.runner] Logstash shut down.

I tried to run the file from the home directory where the logstash is installed and it gives error

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 4, 2019, 8:03pm UTC](https://discuss.elastic.co/t/location-mapping/193615/19 "2019-08-04T20:03:25Z")

</div>

Logstash is starting now... Now you have errors in your .conf file that you're going to need to work through.

The error is right there..

`Expected one of #, => at line 4, column 12 (byte 111) after input{\n file{\n path => " /Users/aadi2391/Desktop/Documents/CIS5900\ Project/crime\ 2.csv "\n start ", :backtrace=>`

I can see you right there you have a backslash`\` instead of a forward slash `/`

Start working through your errors...

You can read the documents here

[https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html](https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html)

You can also add the `-t` option at the end of your current command and it will just test the configuration when it's correct it'll tell you.

---

<div class="post-metadata">

**Author:** ![aaditya\_alekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaditya_alekar/32/49351_2.png) [@aaditya\_alekar](https://discuss.elastic.co/u/aaditya_alekar)\
**Post date:** [August 4, 2019, 8:44pm UTC](https://discuss.elastic.co/t/location-mapping/193615/20 "2019-08-04T20:44:14Z")

</div>

Aadityas-MacBook:documents aadi2391$ logstash -f /Users/aadi2391/Desktop/Documents/logstash-7.2.0/config/logstash-Boston\_Crimes.conf -t  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to /usr/local/Cellar/logstash-full/7.3.0/libexec/logs which is now configured via log4j2.properties  
[2019-08-04T13:35:38,680][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-08-04T13:35:39,247][FATAL][logstash.runner] The given configuration is invalid. Reason: Expected one of #, =\> at line 4, column 12 (byte 110) after input{  
file {  
path =\> " /Users/aadi2391/Desktop/Documents/CIS5900/Project/crime 2.csv "  
start  
[2019-08-04T13:35:39,262][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

This is the error now?

[Next page](https://discuss.elastic.co/t/location-mapping/193615.md?page=2)
