# Making GeoIP work for Kibana Map Visualization

**URL:** <https://discuss.elastic.co/t/making-geoip-work-for-kibana-map-visualization/183790>\
**Category:** Kibana\
**Created:** [May 31, 2019, 9:11pm UTC](https://discuss.elastic.co/t/making-geoip-work-for-kibana-map-visualization/183790 "2019-05-31T21:11:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![psmaan1](https://avatars.discourse-cdn.com/v4/letter/p/c6cbf5/32.png) [@psmaan1](https://discuss.elastic.co/u/psmaan1)\
**Post date:** [May 31, 2019, 9:11pm UTC](https://discuss.elastic.co/t/making-geoip-work-for-kibana-map-visualization/183790/1 "2019-05-31T21:11:01Z")

</div>

Hi,  
ELK Setup : 7.0.1.  
Ingesting Windows event logs using winlogbeat.

I am tagging my events with a tag : "src\_public" and "dest\_public".  
Further, I am using geoip to get Lat/Lon information for these public IP.

Here is my geo IP config:

> filter {  
> if [winlog][event\_data][SourceAddress] and "src\_public" in [tags] {  
> geoip {  
> source =\> "[winlog][event\_data][SourceAddress]"  
> target =\> "src\_geoip" }  
> }
> 
> if [winlog][event\_data][DestAddress] and "dest\_public" in [tags] {  
> geoip {  
> source =\> "[winlog][event\_data][DestAddress]"  
> target =\> "dest\_geoip" }  
> }  
> }  
> Well, this is working and I am getting desired data to search.

When I try to map these events to Kibana Map visualization , I see below error:

> **No Compatible Fields:** The winlogbeat-\* index pattern does not contain any of the following field types: geo\_point\*\*

I understand this is because I am using custom target fields : "src\_geoip" and "dest\_geoip".  
To fix this, I need to update the mapping in my index for these fields so that they have type geo\_point.  
However, I could not figure out how to do it.

I did following already:

> PUT winlogbeat-7.0.1-2019/\_mapping  
> {  
> "properties": {  
> "dest\_geoip": {  
> "dynamic" : true,  
> "properties" : {  
> "ip" : {  
> "type" : "ip"  
> },  
> "latitude" : {  
> "type" : "float"  
> },  
> "location" : {  
> "type" : "geo\_point"  
> },  
> "longitude" : {  
> "type" : "float"} } } } }

#This field is getting created automatically as logstash sends these events to ES.  
\*\*So, I deleted this index \> Created a blank index \> Put above mapping with result {ack : true} \> restarted logstash to send logs to this event. \*\*  
But, this did not help. I went to where I started.

I listed my templates and could not figure out which template is getting applied to my index. None of template returned by below command apply to winlogbeat-\* index.

> curl localhost:9200/\_cat/templates?v&s=name
> 
> name index\_patterns order version  
> .logstash-management [.logstash] 0  
> .ml-notifications [.ml-notifications] 0 7000199  
> .watch-history-9 [.watcher-history-9\*] 2147483647  
> .monitoring-es [.monitoring-es-7-_] 0 7000199  
> .watches [.watches_] 2147483647  
> .monitoring-kibana [.monitoring-kibana-7-_] 0 7000199  
> .monitoring-logstash [.monitoring-logstash-7-_] 0 7000199  
> .management-beats [.management-beats] 0 70000  
> .ml-meta [.ml-meta] 0 7000199  
> .kibana\_task\_manager [.kibana\_task\_manager] 0 7000199  
> .triggered\_watches [.triggered\_watches\*] 2147483647  
> .monitoring-alerts-7 [.monitoring-alerts-7] 0 7000199  
> .ml-state [.ml-state\*] 0 7000199  
> .monitoring-beats [.monitoring-beats-7-_] 0 7000199  
> .ml-anomalies- [.ml-anomalies-_] 0 7000199  
> .ml-config [.ml-config] 0 7000199  
> logstash [logstash-\*] 0 60001

So, I am stuck on how to fix this.

---

<div class="post-metadata">

**Author:** ![psmaan1](https://avatars.discourse-cdn.com/v4/letter/p/c6cbf5/32.png) [@psmaan1](https://discuss.elastic.co/u/psmaan1)\
**Post date:** [May 31, 2019, 9:19pm UTC](https://discuss.elastic.co/t/making-geoip-work-for-kibana-map-visualization/183790/2 "2019-05-31T21:19:38Z")

</div>

The mapping of existing field in elastic is :

> GET winlogbeat-7.0.1-2019/\_mapping/field/dest\*

> "winlogbeat-7.0.1-2019" : {  
> "mappings" : {  
> "dest\_geoip.region\_code" : {  
> "full\_name" : "dest\_geoip.region\_code",  
> "mapping" : {  
> "region\_code" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> "dest\_geoip.region\_name.keyword" : {  
> "full\_name" : "dest\_geoip.region\_name.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.continent\_code.keyword" : {  
> "full\_name" : "dest\_geoip.continent\_code.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.longitude" : {  
> "full\_name" : "dest\_geoip.longitude",  
> "mapping" : {  
> "longitude" : {  
> "type" : "float"  
> }  
> }  
> },  
> "dest\_geoip.location" : {  
> "full\_name" : "dest\_geoip.location",  
> "mapping" : {  
> "location" : {  
> "type" : "geo\_point"  
> }  
> }  
> },  
> "dest\_geoip.region\_code.keyword" : {  
> "full\_name" : "dest\_geoip.region\_code.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.region\_name" : {  
> "full\_name" : "dest\_geoip.region\_name",  
> "mapping" : {  
> "region\_name" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> "dest\_geoip.country\_code2.keyword" : {  
> "full\_name" : "dest\_geoip.country\_code2.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.postal\_code.keyword" : {  
> "full\_name" : "dest\_geoip.postal\_code.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.country\_name.keyword" : {  
> "full\_name" : "dest\_geoip.country\_name.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.dma\_code" : {  
> "full\_name" : "dest\_geoip.dma\_code",  
> "mapping" : {  
> "dma\_code" : {  
> "type" : "long"  
> }  
> }  
> },  
> "dest\_geoip.timezone.keyword" : {  
> "full\_name" : "dest\_geoip.timezone.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.city\_name.keyword" : {  
> "full\_name" : "dest\_geoip.city\_name.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.postal\_code" : {  
> "full\_name" : "dest\_geoip.postal\_code",  
> "mapping" : {  
> "postal\_code" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> "dest\_geoip.timezone" : {  
> "full\_name" : "dest\_geoip.timezone",  
> "mapping" : {  
> "timezone" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> "dest\_geoip.country\_code3.keyword" : {  
> "full\_name" : "dest\_geoip.country\_code3.keyword",  
> "mapping" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "dest\_geoip.latitude" : {  
> "full\_name" : "dest\_geoip.latitude",  
> "mapping" : {  
> "latitude" : {  
> "type" : "float"  
> }  
> }  
> },  
> "dest\_geoip.country\_code2" : {  
> "full\_name" : "dest\_geoip.country\_code2",  
> "mapping" : {  
> "country\_code2" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> "dest\_geoip.continent\_code" : {  
> "full\_name" : "dest\_geoip.continent\_code",  
> "mapping" : {  
> "continent\_code" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> "dest\_geoip.city\_name" : {  
> "full\_name" : "dest\_geoip.city\_name",  
> "mapping" : {  
> "city\_name" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> "dest\_geoip.ip" : {  
> "full\_name" : "dest\_geoip.ip",  
> "mapping" : {  
> "ip" : {  
> "type" : "ip"  
> }  
> }  
> },  
> "dest\_geoip.country\_name" : {  
> "full\_name" : "dest\_geoip.country\_name",  
> "mapping" : {  
> "country\_name" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> }  
> }  
> },  
> }  
> }  
> }

It has update done by me, but that is not helping:

> dest\_geoip.location" : {  
> "full\_name" : "dest\_geoip.location",  
> "mapping" : {  
> "location" : {  
> "type" : "geo\_point"  
> }  
> }  
> },

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2019, 9:19pm UTC](https://discuss.elastic.co/t/making-geoip-work-for-kibana-map-visualization/183790/3 "2019-06-28T21:19:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
