# Missing geo.location

**URL:** <https://discuss.elastic.co/t/missing-geo-location/205595>\
**Category:** Logstash\
**Created:** [October 29, 2019, 6:22am UTC](https://discuss.elastic.co/t/missing-geo-location/205595 "2019-10-29T06:22:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jan\_Kaspar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jan_kaspar/32/44443_2.png) [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Post date:** [October 29, 2019, 6:22am UTC](https://discuss.elastic.co/t/missing-geo-location/205595/1 "2019-10-29T06:22:41Z")

</div>

Hi all,

I would like to ask for help. I am parsing data from our firewall and there are fields containing IP address. I would like to use Coordinates map to visualize accesses. Problem is that i am missing geo.location field in parsed data.

ELK 7.2.0

**logstash config** :

filter {  
if "USG3P" in [tags] {  
grok {  
match =\> {  
"[message]" =\> [  
"%{TIMESTAMP\_ISO8601:date} %{DATA:device} %{DATA:logsource}:\s+[%{DATA:rules.int}-%{DATA:rules.index}-%{DATA:rules.action}]IN=%{DATA:interfaces.input}\s+OUT=%{DATA:interfaces.output}\s+MAC=%{DATA:mac}\s+SRC=%{IPV4:SRC}\s+DST=%{IPV4:DST}\s+LEN=%{INT:LEN}\s+TOS=%{BASE16NUM:TOS}\s+PREC=%{BASE16NUM:PREC}\s+TTL=%{INT:TTL}\s+ID=%{INT:ID}\s+%{DATA:flags}\s+PROTO=%{WORD:PROTO}\s+SPT=%{INT:SPT}\s+DPT=%{INT:DPT}\s+WINDOW=%{INT:WINDOW}\s+RES=%{BASE16NUM:RES}\s+%{WORD:flag1}\s+%{WORD:flag2}\s+%{WORD:flag3}\s+URGP=%{WORD:URGP}%{GREEDYDATA:rest}",  
"%{TIMESTAMP\_ISO8601:date} %{DATA:device} %{DATA:logsource}:\s+[%{DATA:rules.int}-%{DATA:rules.index}-%{DATA:rules.action}]IN=%{DATA:interfaces.input}\s+OUT=%{DATA:interfaces.output}\s+MAC=%{DATA:mac}\s+SRC=%{IPV4:SRC}\s+DST=%{IPV4:DST}\s+LEN=%{INT:LEN}\s+TOS=%{BASE16NUM:TOS}\s+PREC=%{BASE16NUM:PREC}\s+TTL=%{INT:TTL}\s+ID=%{INT:ID}\s+%{DATA:flags}\s+PROTO=%{WORD:PROTO}\s+SPT=%{INT:SPT}\s+DPT=%{INT:DPT}\s+WINDOW=%{INT:WINDOW}\s+RES=%{BASE16NUM:RES}\s+%{WORD:flag1}\s+URGP=%{WORD:URGP}%{GREEDYDATA:rest}"  
]  
}  
}  
geoip {  
source =\> "SRC"  
}  
}  
}

here is index pattern:

 ![index-pattern](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d1eaa1cde77cf9c75a437d2a3f4dbe483716617c.png)

detail of parsed fields: (missing geo.location)

![detail](https://us1.discourse-cdn.com/elastic/original/3X/2/2/223554ec8ab55e65604d52c0128a33267c423488.png)

Any suggestion?

Thank you Jan

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 29, 2019, 2:13pm UTC](https://discuss.elastic.co/t/missing-geo-location/205595/2 "2019-10-29T14:13:37Z")

</div>

Do you have a template similar to the [default](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json) logstash-\* template that tells elasticsearch that geoip.location should be a geo\_point in the filebeat-\* indexes?

---

<div class="post-metadata">

**Author:** ![Jan\_Kaspar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jan_kaspar/32/44443_2.png) [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Post date:** [October 29, 2019, 2:33pm UTC](https://discuss.elastic.co/t/missing-geo-location/205595/3 "2019-10-29T14:33:03Z")

</div>

Hi Badger,

thanks for answer. Look at my first screenshot. there is geo.location. I already tryed to use that. but it didnt worked.

My be I am using it wrong because I am getting this error:

"error" : {  
"root\_cause" : [  
{  
"type" : "mapper\_parsing\_exception",  
"reason" : "Root mapping definition has unsupported parameters: [_default_ : {dynamic\_templates=[{message\_field={path\_match=message, mapping={norms=false, type=text}, match\_mapping\_type=string}}, {string\_fields={mapping={norms=false, type=text, fields={keyword={ignore\_above=256, type=keyword}}}, match\_mapping\_type=string, match=_}}], properties={@timestamp={type=date}, geoip={dynamic=true, properties={ip={type=ip}, latitude={type=half\_float}, location={type=geo\_point}, longitude={type=half\_float}}}, @version={type=keyword}}}]"  
}  
],  
"type" : "mapper\_parsing\_exception",  
"reason" : "Failed to parse mapping [\_doc]: Root mapping definition has unsupported parameters: [default : {dynamic\_templates=[{message\_field={path\_match=message, mapping={norms=false, type=text}, match\_mapping\_type=string}}, {string\_fields={mapping={norms=false, type=text, fields={keyword={ignore\_above=256, type=keyword}}}, match\_mapping\_type=string, match=_}}], properties={@timestamp={type=date}, geoip={dynamic=true, properties={ip={type=ip}, latitude={type=half\_float}, location={type=geo\_point}, longitude={type=half\_float}}}, @version={type=keyword}}}]",  
"caused\_by" : {  
"type" : "mapper\_parsing\_exception",  
"reason" : "Root mapping definition has unsupported parameters: [_default_ : {dynamic\_templates=[{message\_field={path\_match=message, mapping={norms=false, type=text}, match\_mapping\_type=string}}, {string\_fields={mapping={norms=false, type=text, fields={keyword={ignore\_above=256, type=keyword}}}, match\_mapping\_type=string, match=\*}}], properties={@timestamp={type=date}, geoip={dynamic=true, properties={ip={type=ip}, latitude={type=half\_float}, location={type=geo\_point}, longitude={type=half\_float}}}, @version={type=keyword}}}]"  
}  
},  
"status" : 400  
}

Jan

---

<div class="post-metadata">

**Author:** ![Jan\_Kaspar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jan_kaspar/32/44443_2.png) [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Post date:** [October 29, 2019, 5:23pm UTC](https://discuss.elastic.co/t/missing-geo-location/205595/4 "2019-10-29T17:23:06Z")

</div>

Solved with this finaly:

curl -X PUT "localhost:9200/\_template/filebeat-7.2.0?pretty" -H 'Content-Type: application/json' -d'  
{  
"index\_patterns": ["filebeat-_"],  
"settings": {  
"number\_of\_shards": 1  
},  
"mappings" : {  
"dynamic\_templates" : [ {  
"message\_field" : {  
"path\_match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text",  
"norms" : false  
}  
}  
}, {  
"string\_fields" : {  
"match" : "_",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text", "norms" : false,  
"fields" : {  
"keyword" : { "type": "keyword", "ignore\_above": 256 }  
}  
}  
}  
} ],  
"properties" : {  
"@timestamp": { "type": "date"},  
"@version": { "type": "keyword"},  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "half\_float" },  
"longitude" : { "type" : "half\_float" }  
}  
}  
}  
}  
}  
'

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2019, 5:23pm UTC](https://discuss.elastic.co/t/missing-geo-location/205595/5 "2019-11-26T17:23:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
