# Mapping geo\_point data type in logstash

**URL:** <https://discuss.elastic.co/t/mapping-geo-point-data-type-in-logstash/155672>\
**Category:** Logstash\
**Created:** [November 7, 2018, 7:45am UTC](https://discuss.elastic.co/t/mapping-geo-point-data-type-in-logstash/155672 "2018-11-07T07:45:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chinmoyd](https://avatars.discourse-cdn.com/v4/letter/c/e495f1/32.png) [@chinmoyd](https://discuss.elastic.co/u/chinmoyd)\
**Post date:** [November 7, 2018, 7:45am UTC](https://discuss.elastic.co/t/mapping-geo-point-data-type-in-logstash/155672/1 "2018-11-07T07:45:38Z")

</div>

In my input JSON to logstash( input from a postgreSQL query), I have a string field containing the geolocation(example: 22.572645, 88.363892). The field name is payergeocode. When this data is going to Kibana through Elasticsearch, it is not getting any geo\_point data type. Please suggest what do I need to write in logstash.conf that will do the conversion.

I have tried the following and it did not work.  
filter{  
if [type] == "cases"{  
mutate{  
convert =\> {  
"payergeocode" =\> "geo\_point"  
}  
}  
}  
}

Logstash version is 6.4.2. Elasticsearch version is 6.4.2

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 7, 2018, 7:59am UTC](https://discuss.elastic.co/t/mapping-geo-point-data-type-in-logstash/155672/2 "2018-11-07T07:59:54Z")

</div>

Converting fields in a mutate block just changes how they are represented in the JSON document sent to Elasticsearch. As `geo_point` fields are not represented in any special way in the JSON document, but rather interpreted in Elasticsearch, you can not cast this in Logstash. You instead need to use an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/indices-templates.html) that contains the correct mapping.

---

<div class="post-metadata">

**Author:** ![chinmoyd](https://avatars.discourse-cdn.com/v4/letter/c/e495f1/32.png) [@chinmoyd](https://discuss.elastic.co/u/chinmoyd)\
**Post date:** [November 7, 2018, 9:13am UTC](https://discuss.elastic.co/t/mapping-geo-point-data-type-in-logstash/155672/3 "2018-11-07T09:13:24Z")

</div>

Thanks for the quick reply.

I have created a mapping as below:  
[http://172.18.17.207:9200/\_template/geotypetemplate\_2](http://172.18.17.207:9200/_template/geotypetemplate_2)  
{  
"index\_patterns" : ["case\*"],  
"mappings": {  
"doc": {  
"properties": {  
"case\_id": {  
"type": "keyword"  
},  
"crtn\_ts": {  
"type": "date"  
},  
"payergeocode": {  
"type": "geo\_point"  
}  
}  
}  
}  
}

My SQL query is: select case\_id, crtn\_ts, payergeocode from frm\_gateway.frm\_case

But when I start logstash, Elasticsearch gives the following error:  
[2018-11-07T14:35:04,766][DEBUG][o.e.a.b.TransportShardBulkAction] [casegs][0] failed to execute bulk item (update) BulkShardRequest [[casegs][0]] containing [update {[casegs][caseg][ISBIC05112018100001], doc\_as\_upsert[true], doc[index {[casegs][caseg][ISBIC05112018100001], source[{"case\_id":"ISBIC05112018100001","@timestamp":"2018-11-07T09:05:01.233Z","payergeocode":"22.572645,88.363892","type":"cases","@version":"1","crtn\_ts":"2018-11-05T07:15:39.253Z"}]}], scripted\_upsert[false], detect\_noop[true]}]  
java.lang.IllegalArgumentException: Rejecting mapping update to [casegs] as the final mapping would have more than 1 type: [caseg, doc]

Output in logstash.conf is as below:  
output {  
stdout { codec =\> rubydebug }  
if [type] == "cases"{  
elasticsearch {  
index =\> "casegs"  
document\_type =\> "caseg"  
document\_id =\> "%{case\_id}"  
doc\_as\_upsert =\> true  
action =\> "update"  
hosts =\> ["172.18.17.207:9200"]  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2018, 9:26am UTC](https://discuss.elastic.co/t/mapping-geo-point-data-type-in-logstash/155672/4 "2018-12-05T09:26:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
