# Manually Setting Geoip.Location

**URL:** <https://discuss.elastic.co/t/manually-setting-geoip-location/176429>\
**Category:** Logstash\
**Created:** [April 11, 2019, 2:54pm UTC](https://discuss.elastic.co/t/manually-setting-geoip-location/176429 "2019-04-11T14:54:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Berry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_berry/32/42816_2.png) [@David\_Berry](https://discuss.elastic.co/u/David_Berry)\
**Post date:** [April 11, 2019, 2:54pm UTC](https://discuss.elastic.co/t/manually-setting-geoip-location/176429/1 "2019-04-11T14:54:14Z")

</div>

Hello Folks,

I am looking for a way to manually set the geo location of various Logstash servers. While these Logstash server are all separated geographically, they are collecting logs and beats from servers that don't have public IP connections. Individual user IPs aren't interesting for my use cases either (none are public), so the usual recommendations using the GeoLite2 City database won't work for me.

What I am attempting is to enrich the indexes with geoip.location being statically set. From ingest at Logstash, this is what I've done at the end of all the log filtering, using mutate to manually add the field. (my first attempt is commenetd out).

```
mutate {
  add_field => ["[geoip][location]", "-79.3849" ]
  add_field => ["[geoip][location]", "43.6529" ]
}

```

Here is the mapping I'm using in the template, which matches all of these log indexes.

```
"geoip": {
            "dynamic": true,
            "properties": {
              "ip": {
                "type": "ip"
              },
              "location": {
                "type": "geo_point"
              },
              "latitude": {
                "type": "half_float"
              },
              "longitude": {
                "type": "half_float"
              }

```

However, I can see that the geoip.location type appears as a string when I explore the index patterns for these logs.

`geoip.location -> string`

And when I Discover the data in the index pattern, I can see it present, but as a string type (should be a globe symbol I believe in this view).

`t geoip.location -79.3849, 43.6529`

So, it seems like my mapping isn't working. I can confirm the index\_patterns in the template matches, so I'm not sure what the problem is...

Regards,

David

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 11, 2019, 3:13pm UTC](https://discuss.elastic.co/t/manually-setting-geoip-location/176429/2 "2019-04-11T15:13:28Z")

</div>

> [@David\_Berry](#):
>
> mutate { add\_field =\> ["[geoip][location]", "-79.3849" ] add\_field =\> ["[geoip][location]", "43.6529" ] }

Shouldn't that be [geoip][location][lat] and [geoip][location][lon]?

Just found an interesting anomaly in logstash configuration parsing. Using arrays

```
 mutate { add_field => ["[geoip][location]" , "foo" ] add_field => ["[geoip][location]" , "bar" ] }

```

results in

```
     "geoip" => {
    "location" => [
        [0] "foo",
        [1] "bar"
    ]
},

```

Whereas using hashes

```
 mutate { add_field => { "[geoip][location]" => "foo" } add_field => { "[geoip][location]" => "bar" } }

```

results in

```
     "geoip" => {
    "location" => "bar"
},

```

That will come in useful one day 😃

---

<div class="post-metadata">

**Author:** ![David\_Berry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_berry/32/42816_2.png) [@David\_Berry](https://discuss.elastic.co/u/David_Berry)\
**Post date:** [April 11, 2019, 4:07pm UTC](https://discuss.elastic.co/t/manually-setting-geoip-location/176429/3 "2019-04-11T16:07:26Z")

</div>

Hi,

yes I can do it this way too:

#Logstash pipeline

```
  mutate {
    add_field => ["[geoip][location][longitude]", "-79.3849" ]
    add_field => ["[geoip][location][latitude]", "43.6529" ]
    }

```

I refreshed the index pattern, as well as the actual indices. Still see these as strings though. Shouldn't they end up as a geo\_point type?

```
t geoip.location.latitude 43.6529
t geoip.location.longitude -79.3849
```

---

<div class="post-metadata">

**Author:** ![David\_Berry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_berry/32/42816_2.png) [@David\_Berry](https://discuss.elastic.co/u/David_Berry)\
**Post date:** [April 11, 2019, 4:13pm UTC](https://discuss.elastic.co/t/manually-setting-geoip-location/176429/4 "2019-04-11T16:13:35Z")

</div>

oh well no, they are float types.

But location itself "should" be....

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 11, 2019, 4:41pm UTC](https://discuss.elastic.co/t/manually-setting-geoip-location/176429/5 "2019-04-11T16:41:48Z")

</div>

> [@David\_Berry](#):
>
> add\_field =\> ["[geoip][location][longitude]", "-79.3849" ] add\_field =\> ["[geoip][location][latitude]", "43.6529" ]

A geoip has latitude and longitude fields in it, but a geo\_point (i.e. [geoip][location]) has lat and lon fields in it.

It does not matter whether you convert them to float or not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2019, 4:41pm UTC](https://discuss.elastic.co/t/manually-setting-geoip-location/176429/6 "2019-05-09T16:41:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
