# LogStash, GeoJSON and Kibana

**URL:** <https://discuss.elastic.co/t/logstash-geojson-and-kibana/277450>\
**Category:** Logstash\
**Created:** [June 30, 2021, 10:49am UTC](https://discuss.elastic.co/t/logstash-geojson-and-kibana/277450 "2021-06-30T10:49:02Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 2, 2021, 2:24am UTC](https://discuss.elastic.co/t/logstash-geojson-and-kibana/277450/5 "2021-07-02T02:24:43Z")

</div>

The default template that an elasticsearch output uses [maps](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/476097712b67e0452099769b2c8b0ef6e63e40eb/lib/logstash/outputs/elasticsearch/templates/ecs-disabled/elasticsearch-7x.json#L33) a field called [geoip] to include a [geoip][location] which is a geo\_point. [geoip] matches the default target of a geoip filter, so yes, that one get mapped "automatically".

If you do not set the mapping no other field will be a geo\_point. I understand that dynamic mapping is really helpful, that's why it is there. But remember, you can still use dynamic mapping for everything else except your geo\_point fields.

Note also that you may not even need to know where in your document structure those geo\_points are if you can name them consistently. The dynamic template [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-templates.html) includes an example that shows how anything that arrives in elasticsearch as a string and whose name starts with "ip" can be mapped as type ip. I have not tested it but I expect that you could create a template that maps any field whose name ends in "location" as a geo\_point.

And remember that when sending a geo\_point to elastic you do not have to send it as an array of two floats. You have [five options](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html), including a string like "41.12,-71.34". elasticsearch knows how to parse that once the field is mapped as a geo\_point.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-geojson-and-kibana/277450)._
